CVE-2025-49083 Details
Description
CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and there are no attack requirements. Privileges required are high and there is no user interaction required. The impact to confidentiality is low, impact to integrity is high and there is no impact to availability. The impact to the confidentiality and integrity of subsequent systems is low and there is no subsequent system impact to availability.
A deserialization vulnerability has been identified in the management console of Absolute Secure Access, affecting versions after 12.00 and prior to 13.56. This vulnerability allows attackers with administrative access to the console to manipulate unsafe content, leading to execution in the console's security context. The vulnerability arises from insufficient input validation, with a low attack complexity and no user interaction required. While the vulnerability has a low impact on confidentiality, it significantly compromises integrity. Additionally, there is minimal impact on the confidentiality and integrity of subsequent systems, with no effect on their availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49083 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| absolute secure access | >= 12.00, < 13.56 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | Initial Analysis | [email protected] |
| Jul 31, 2025 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | New CVE Received | [email protected] |