Impact
A memory management error exists in Secure Access servers prior to version 14.55. This flaw allows an attacker with intimate knowledge of and full control over the tunnel protocol to trigger a persistent denial of service, making the server unavailable to legitimate users. The root cause is uncontrolled resource consumption, classified as CWE-400.
Affected Systems
Absolute Security’s Secure Access servers running any version before 14.55 are vulnerable. These servers are exposed to the tunnel protocol that the attacker must manipulate to exhaust resources.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating high severity, but the EPSS score is under 1%, signifying a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires deep understanding of the proprietary tunnel protocol and full authority over the connection, the attack vector is likely restricted to trusted or compromised clients and is not easily achievable by a generic attacker.
OpenCVE Enrichment