PT-2025-40423 · Unknown · Secure Access

Published

2025-10-02

·

Updated

2025-10-16

·

CVE-2025-54089

CVSS v4.0

4.6

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions secure access versions prior to 14.10
Description This issue is a cross-site scripting condition. An attacker with administrative access to the console can disrupt another administrator's access. The attack complexity is low, and no specific requirements are needed for the attack to succeed. High privileges are required to carry out the attack, and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, but there is a low impact to integrity.
Recommendations Update to version 14.10 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54089

Affected Products

Secure Access