CVE-2025-15553

Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*

History

20 Apr 2026, 13:18

Type Values Removed Values Added
CPE cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*
References () https://labs.reversec.com/advisories/2026/03/insecure-logout-functionality-in-truesec-lapswebui - () https://labs.reversec.com/advisories/2026/03/insecure-logout-functionality-in-truesec-lapswebui - Third Party Advisory
Summary
  • (es) La funcionalidad de cierre de sesión no operativa en LAPSWebUI de Truesec antes de la versión 2.4 permite a un atacante con acceso a una estación de trabajo escalar sus privilegios mediante la divulgación de la contraseña de administrador local.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
First Time Truesec
Truesec lapswebui

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-04-20 13:18


NVD link : CVE-2025-15553

Mitre link : CVE-2025-15553

CVE.ORG link : CVE-2025-15553


JSON object : View

Products Affected

truesec

  • lapswebui
CWE
CWE-613

Insufficient Session Expiration