Impact
This vulnerability stems from improper memory handling in Secure Access clients and servers. The flaw allows attackers with intimate knowledge of the tunnel protocol to trigger a non-persistent denial of service by sending a crafted tunnel message that causes improper buffer management and resource exhaustion, as indicated by the cited CWEs. The result is a temporary loss of service availability for legitimate users while the server recovers.
Affected Systems
Absolute Security's Secure Access is affected. Deployments running any version prior to 14.55 are vulnerable and must be upgraded to a supported release to eliminate the risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must have direct control over the tunnel protocol—typically an insider or a compromised client—to exploit the vulnerability, limiting the attack path to environments where such control can be established. Nonetheless, once successful, it results in a denial of service to legitimate users until the server recovers.
OpenCVE Enrichment