Impact
This vulnerability allows an attacker to trigger a persistent denial of service by sending a malformed response during the authentication process. The flaw occurs entirely within the authentication subsystem of Secure Access servers and can cause the service to become unresponsive once the malformed data is processed. The primary impact is a loss of availability for the authentication service, potentially cascading to downstream services relying on authentication, and leading to service disruption without any requirement for user credentials.
Affected Systems
Absolute Security’s Secure Access product is affected in all releases prior to version 14.60. The issue is specific to the authentication component of the server and does not affect other modules of the product.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. While an EPSS score is not provided, the lack of availability does not mean low exploitation probability; the flaw can be triggered remotely by an attacker with network access to the authentication interface. Because the vulnerability is listed as not in KEV, there is no evidence of known active exploitation, yet the high severity and ability to cause service outage make it a significant risk to availability.
OpenCVE Enrichment