Impact
An integer underflow occurs in the traffic parsing routine of Absolute Security’s Secure Access client before version 14.55. When a malformed tunnel packet is processed, the underflow corrupts an internal counter, causing the client to crash or restart. The flaw does not reveal data or grant elevated privileges; it only disrupts the availability of the affected client.
Affected Systems
All installations of the Secure Access client released prior to 14.55 are vulnerable. This includes every pre‑14.55 build of the client, as no sub‑identifiers indicate a narrower scope.
Risk and Exploitability
The CVSS score of 2.1 classifies the vulnerability as low severity, and the EPSS score of less than 1% suggests exploitation is rare but still possible. The flaw is not listed in CISA’s KEV catalog. Attackers must have intimate knowledge of the tunnel protocol and total control over the traffic they send, implying a privileged or compromised environment where the attacker can dictate tunnel traffic. The resulting damage is a non‑persistent denial of service that does not compromise data or network configuration.
OpenCVE Enrichment