PT-2026-25675 · Truesec · Lapswebui

CVE-2025-15552

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Truesec’s LAPSWebUI versions prior to 2.4
Description A flaw exists in Truesec’s LAPSWebUI that relates to insufficient session expiration. An attacker gaining access to a workstation may be able to elevate their privileges through the disclosure of a local administrator password.
Recommendations Update Truesec’s LAPSWebUI to version 2.4 or later.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15552

Produtos afetados

Lapswebui