An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
History

Tue, 26 Aug 2025 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Securden
Securden unified Pam
Vendors & Products Securden
Securden unified Pam

Mon, 25 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Title Securden Unified PAM Authentication Bypass
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2025-08-25T16:06:03.962Z

Updated: 2025-08-25T20:32:32.947Z

Reserved: 2025-06-26T09:06:04.496Z

Link: CVE-2025-53118

cve-icon Vulnrichment

Updated: 2025-08-25T20:32:27.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-25T16:15:31.023

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-53118

cve-icon Redhat

No data.