CVE-2025-6737 Details
Description
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.
A vulnerability exists in Securden's Unified PAM Remote Vendor Gateway access portal, which shares infrastructure and access tokens across multiple tenants. This flaw allows a malicious actor to obtain authentication materials and access the gateway server with low-privilege permissions. The issue arises from the shared SSH key infrastructure, which can be exploited to access vendor login pages on the internet, potentially leading to further exploitation of other customers running Securden Unified PAM.
Customers should update Securden Unified PAM to version 11.4.4 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 25, 2025CISA-ADP
Assessed Aug 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/ | [email protected] | AdvisoryBundleExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Securden Unified PAM | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 25, 2025 | New CVE Received | [email protected] |
Volerion