VYPR

Unified Pam

by Securden

CVEs (2)

  • CVE-2025-53118CriAug 25, 2025
    risk 0.66cvss 9.8epss 0.29

    An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

  • CVE-2025-53120CriAug 25, 2025
    risk 0.62cvss 9.4epss 0.09

    A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server.