Impact
A memory disclosure exists in the Secure Access client before version 14.55 that can expose a small amount of random memory. The vulnerability is classified as CWE‑200, a weakness that can leak sensitive data and potentially enable attackers to obtain confidential information from the client process.
Affected Systems
Absolute Security Secure Access client users with installed releases earlier than version 14.55 are vulnerable. Any instance of the client exposed through a tunnel is susceptible if the attacker controls the tunnel protocol.
Risk and Exploitability
The CVSS score of 2.1 indicates limited impact, and the EPSS score of less than 1 % reflects a very low likelihood of exploitation under current conditions. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that exploitation requires intimate knowledge of and full control over the tunnel protocol, implying that only attackers with privileged network access or insider capabilities could trigger the memory leak. Therefore, the overall risk remains low but should be mitigated by updating the software and limiting tunnel control to trusted hosts.
OpenCVE Enrichment