cve-2025-53118
CRITICAL CVSS 9.8 opencve
Description
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Timeline
- Published
- 2025-08-25 16:15 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
mitre | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2025-53118",
"enrichment": {
"created": "2025-08-26T07:25:08.702470+00:00",
"updated": "2025-08-26T07:25:08.702535+00:00",
"vendors": [
"securden",
"securden$PRODUCT$unified_pam"
]
},
"epss": {
"score": 0.30525
},
"mitre": {
"cpes": [],
"created": "2025-08-25T16:06:03.962000+00:00",
"description": "An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2025/53xxx/CVE-2025-53118.json",
"references": [
"https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/"
],
"title": "Securden Unified PAM Authentication Bypass",
"updated": "2025-08-25T20:32:32.947000+00:00",
"vendors": [],
"weaknesses": [
"CWE-306"
]
},
"nvd": {
"cpes": [],
"created": "2025-08-25T16:15:31.023000+00:00",
"description": "An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2025/CVE-2025-53118.json",
"references": [
"https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/"
],
"title": null,
"updated": "2026-06-17T09:37:39.083000+00:00",
"vendors": [],
"weaknesses": [
"CWE-306"
]
},
"opencve": {
"changes": [
{
"created": "2025-08-25T21:45:00+00:00",
"data": [
{
"details": {
"new": "An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "Securden Unified PAM Authentication Bypass",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-306"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "a498f8b2-10a4-4d60-9a51-22fd9a9aa445"
},
{
"created": "2025-08-26T07:30:00+00:00",
"data": [
{
"details": [
"securden",
"securden$PRODUCT$unified_pam"
],
"type": "first_time"
},
{
"details": {
"added": [
"securden",
"securden$PRODUCT$unified_pam"
],
"removed": []
},
"type": "vendors"
}
],
"id": "6443b3d4-08c1-4714-9ef0-475083e2c94f"
}
],
"cpes": {
"data": [],
"providers": []
},
"created": {
"data": "2025-08-25T16:06:03.962000+00:00",
"provider": "mitre"
},
"description": {
"data": "An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.30525
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Securden Unified PAM Authentication Bypass",
"provider": "mitre"
},
"updated": {
"data": "2026-04-15T00:35:42.020000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"securden",
"securden$PRODUCT$unified_pam"
],
"providers": [
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-306"
],
"providers": [
"mitre",
"nvd"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2025-08-25T16:06:03.962000+00:00",
"description": "An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": "Securden Unified PAM Authentication Bypass",
"updated": "2025-08-25T20:32:27.580000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2025/53xxx/CVE-2025-53118.json",
"weaknesses": []
}
}
Enrichment data
Aggregated bundle (all enrichments)