CVE-2025-27702

EUVD-2025-16358
CVE-2025-27702 is a vulnerability in the management console of Absolute 
Secure Access prior to version 13.54. Attackers with administrative 
access to the console and who have been assigned a certain set of 
permissions can bypass those permissions to improperly modify settings. 
The attack complexity is low, there are no preexisting attack 
requirements; the privileges required are high, and there is no user 
interaction required. There is no impact to system confidentiality or 
availability, impact to system integrity is high.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
absolutesecure_access
𝑥
< 13.54
𝑥
= Vulnerable software versions