CVE-2025-27702

CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. There is no impact to system confidentiality or availability, impact to system integrity is high.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

04 Jun 2025, 15:37

Type Values Removed Values Added
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
References () https://www.absolute.com/platform/vulnerability-archive/cve-2025-27702 - () https://www.absolute.com/platform/vulnerability-archive/cve-2025-27702 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Absolute secure Access
Absolute
Summary
  • (es) CVE-2025-27702 es una vulnerabilidad en la consola de administración de Absolute Secure Access anterior a la versión 13.54. Los atacantes con acceso administrativo a la consola y con ciertos permisos asignados pueden eludirlos para modificar la configuración de forma indebida. La complejidad del ataque es baja, no existen requisitos previos; se requieren privilegios elevados y no se requiere interacción del usuario. No se ve afectada la confidencialidad ni la disponibilidad del sistema, pero sí la integridad del mismo.

29 May 2025, 00:15

Type Values Removed Values Added
CWE CWE-284

28 May 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 21:15

Updated : 2025-06-04 15:37


NVD link : CVE-2025-27702

Mitre link : CVE-2025-27702

CVE.ORG link : CVE-2025-27702


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-284

Improper Access Control