Truesec Vulnerabilities and Affected Products
Vulnerabilities associated with LAPSWebUI.
Products
Clear product- LAPSWebUI3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-15554MEDIUM | Admin Passwords Cached by Browsers in Truesec LAPSWebUIBrowser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords. CWE-525Mar 16, 2026 | CVSS6.0v4.0 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15553MEDIUM | Insecure Logout Functionality in Truesec LAPSWebUINon-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password. CWE-613Mar 16, 2026 | CVSS6.0v4.0 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15552MEDIUM | Long Session Lifetime in Truesec LAPSWebUIInsufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password. CWE-613Mar 16, 2026 | CVSS6.0v4.0 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |