PT-2025-40423 · Unknown · Secure Access
Published
2025-10-02
·
Updated
2025-10-16
·
CVE-2025-54089
CVSS v4.0
4.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
secure access versions prior to 14.10
Description
This issue is a cross-site scripting condition. An attacker with administrative access to the console can disrupt another administrator's access. The attack complexity is low, and no specific requirements are needed for the attack to succeed. High privileges are required to carry out the attack, and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, but there is a low impact to integrity.
Recommendations
Update to version 14.10 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Access