PT-2025-40421 · Unknown · Secure Access

Published

2025-10-02

·

Updated

2025-10-16

·

CVE-2025-54087

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Secure Access versions prior to 14.10
Description A server-side request forgery condition exists in Secure Access. Individuals with administrative rights can submit a specially designed HTTP request from the Secure Access server. The attack requires user interaction and has a high complexity. There is no direct impact to confidentiality, integrity, or availability, but there is a low severity subsequent system impact to integrity.
Recommendations Update to version 14.10 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54087

Affected Products

Secure Access