Impact
The vulnerability is an input validation error in Absolute Security Secure Access clients before version 14.55. An attacker who has intimate knowledge of, and full control over, the tunnel protocol can craft malformed input that causes the client to terminate or become unresponsive, resulting in a non-persistent denial of service. The weakness originates from improper input handling and is classified as CWE‑20.
Affected Systems
Absolute Security’s Secure Access product is affected; any installation of the client that is earlier than version 14.55 is vulnerable. Later releases, starting with 14.55, are not impacted.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity; the EPSS score is reported as less than 1 %, implying a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited known exploitation. Based on the description, the likely attack vector requires an adversary with extensive knowledge of the tunnel protocol and direct control over the communication channel. Therefore, the practical attack vector is limited to an entity with privileged or compromised tunnel access rather than a broad remote attacker.
OpenCVE Enrichment