CVE-2025-15552

Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*

History

20 Apr 2026, 13:29

Type Values Removed Values Added
References () https://labs.reversec.com/advisories/2026/03/long-session-lifetime-in-truesec-lapswebui - () https://labs.reversec.com/advisories/2026/03/long-session-lifetime-in-truesec-lapswebui - Third Party Advisory
CPE cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Expiración de sesión insuficiente en LAPSWebUI de Truesec anterior a la versión 2.4 permite a un atacante con acceso a una estación de trabajo escalar sus privilegios mediante la divulgación de la contraseña de administrador local.
First Time Truesec
Truesec lapswebui

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-04-20 13:29


NVD link : CVE-2025-15552

Mitre link : CVE-2025-15552

CVE.ORG link : CVE-2025-15552


JSON object : View

Products Affected

truesec

  • lapswebui
CWE
CWE-613

Insufficient Session Expiration