Securden Unified PAM是美国Securden公司的一个特权访问管理软件。 Securden Unified PAM存在安全漏洞,该漏洞源于身份验证绕过,可能导致管理员备份功能被控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Securden | Unified PAM | 9.0.* ~ 11.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53118.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-53120 | 9.4 CRITICAL | Securden Unified PAM Path Traversal In File Upload |
| CVE-2025-53119 | 7.5 HIGH | Securden Unified PAM Unauthenticated Unrestricted File Upload |
| CVE-2025-6737 | 7.2 HIGH | Securden Unified PAM Shared SSH Key and Cloud Infrastructure |
No comments yet