CVE-2025-54087: Server-side request forgery in Secure Access
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54087?
CVE-2025-54087 has a high severity rating due to its potential for exploitation by attackers with administrative privileges.
How do I fix CVE-2025-54087?
To fix CVE-2025-54087, upgrade Secure Access to version 14.10 or later immediately.
Who is affected by CVE-2025-54087?
CVE-2025-54087 affects all versions of Secure Access prior to version 14.10.
What kind of vulnerability is CVE-2025-54087?
CVE-2025-54087 is classified as a server-side request forgery (SSRF) vulnerability.
Can CVE-2025-54087 be exploited remotely?
CVE-2025-54087 requires administrative privileges, making remote exploitation complex but still possible.