Filtered by vendor Securden
Subscriptions
Filtered by product Unified Pam
Subscriptions
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-53119 | 1 Securden | 1 Unified Pam | 2025-08-26 | 7.5 High |
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server. | ||||
CVE-2025-6737 | 1 Securden | 1 Unified Pam | 2025-08-26 | 7.2 High |
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions. | ||||
CVE-2025-53120 | 1 Securden | 1 Unified Pam | 2025-08-26 | 9.4 Critical |
A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server. | ||||
CVE-2025-53118 | 1 Securden | 1 Unified Pam | 2025-08-26 | 9.8 Critical |
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM. |
Page 1 of 1.