CVE-2025-53119
7.5Securden · Unified PAM
An unauthenticated unrestricted file upload vulnerability in Securden Unified PAM allows remote attackers to upload malicious binaries or scripts to the server.
Executive summary
A critical, unauthenticated file upload vulnerability in Securden Unified PAM enables remote attackers to inject malicious files, posing a severe risk of system compromise.
Vulnerability
The application suffers from an unrestricted file upload flaw (CWE-434), which permits an unauthenticated attacker to bypass security controls and upload dangerous file types directly to the server infrastructure.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution by uploading malicious scripts or binaries. This could lead to a total compromise of the Privileged Access Management (PAM) environment, resulting in unauthorized access to sensitive credentials, internal lateral movement, and complete loss of system confidentiality and integrity. Given the 7.5 CVSS score, this represents a significant risk to organizational security posture.
Remediation
Immediate Action: Upgrade to the latest version of Securden Unified PAM as directed by the vendor advisory to resolve the file upload restriction flaw.
Proactive Monitoring: Review server access logs for suspicious file uploads, specifically looking for unexpected file extensions or unauthorized POST requests to upload endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block file uploads that contain executable extensions or suspicious file signatures until the patch can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The ability for an unauthenticated user to upload arbitrary files is a critical security failure that must be addressed immediately. Organizations currently running Securden Unified PAM versions 9.0 through 11.3.1 should prioritize this update within their next maintenance cycle to prevent potential remote exploitation.
Sources
Originally found and disclosed by Aaron Herndon, Principal Security Consultant, and Marcus Chang, Security Consultant, both of Rapid7., per the CVE Program record.