Impact
A memory management flaw in Secure Access servers allows an attacker who has intimate knowledge of, and total control over, the tunnel protocol to cause a non‑persistent denial of service. The exploit triggers a resource exhaustion condition that drops normal traffic but does not permanently compromise the host. The vulnerability is identified by CWE‑119 and CWE‑400, indicating improper bounds checks leading to memory corruption and uncontrolled resource usage.
Affected Systems
Absolute Security’s Secure Access servers, versions before 14.55, are susceptible. The flaw is present in all builds of the product that have not applied the update to 14.55 or later, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 6.9 reflects a medium‑to‑high severity impact, but the EPSS score of < 1% indicates that exploitation attempts are expected to be rare. Because the vulnerability requires control over the tunnel protocol, the attack vector is likely limited to insiders or compromised remote partners; it is not an arbitrary remote exploit. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits, yet its ability to continuously disrupt service warrants preemptive action.
OpenCVE Enrichment