Impact
This vulnerability causes a null dereference in the load‑balancing subsystem of Absolute Security Secure Access servers when an unauthenticated packet is received. The resulting crash stops the internal load balancer, yet the server remains operational and can still hand off client connections, so the overall availability impact is moderate rather than a full shutdown.
Affected Systems
Absolute Security:Secure Access servers running any version prior to 14.57 and having load balancing enabled are affected; newer releases are not mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Attackers can exploit the flaw remotely without authentication by sending crafted packets to the load balancer. Because the EPSS score is not available and the vulnerability is not in CISA’s KEV catalog, the likelihood of widespread exploitation appears low, but the impact remains significant for affected environments.
OpenCVE Enrichment