Impact
Vulnerable versions of Secure Access allow an authenticated attacker to send malformed data during client registration, which triggers a persistent denial of service by causing the server to crash or become unresponsive. The issue stems from insufficient input validation, falling under CWE‑20, and results in loss of availability for the affected service.
Affected Systems
Absolute Security’s Secure Access product is affected in all releases prior to version 14.60. Administrators need to verify that any deployed instances are running 14.60 or later to avoid exploitation.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of exploitation in the wild cannot be precisely quantified. As the flaw requires authenticated access, attackers must possess valid credentials or compromise an account to submit the malformed data; once they do, the denial of service is persistent and can affect all users of the Secure Access service.
OpenCVE Enrichment