CVE-2025-49081
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-06-12

Last updated on: 2025-06-17

Assigner: NetMotion Software

Description
There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrative UI by writing invalid data to the warehouse over the network. The attack complexity is low, there are no attack requirements, privileges required are high, and there is no user interaction required. There is no impact on confidentiality or integrity; the impact on availability is high.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-06-12
Last Modified
2025-06-17
Generated
2026-05-07
AI Q&A
2025-06-12
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
absolute secure_access to 13.55 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an insufficient input validation issue in the warehouse component of Absolute Secure Access versions prior to 13.55. Attackers who have system administrator privileges can send invalid data over the network to the warehouse, which impairs the availability of the Secure Access administrative user interface. The attack is of low complexity, requires no user interaction, but does require high privileges. It affects availability only, without impacting confidentiality or integrity. [1]


How can this vulnerability impact me? :

If exploited, this vulnerability can impair the availability of the Secure Access administrative UI, potentially causing downtime or disruption in managing the Secure Access system. Since it affects availability, it could prevent administrators from accessing or managing the system effectively, but it does not compromise data confidentiality or integrity. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade Absolute Secure Access to server version 13.55 or later, as versions prior to 13.55 are affected. Additionally, restrict system administrator privileges to trusted personnel only, since the vulnerability requires high privileges to exploit. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart