Impact
A flaw in the connection set‑up subsystem of Secure Access allows an unauthenticated attacker to send specially crafted traffic that forces the server to fall into a state of persistent unresponsiveness. The result is a denial of service that can halt legitimate users from accessing the service. This vulnerability is a classic example of a remote DoS that does not require authentication to exploit, and the effect is a loss of availability on the affected servers.
Affected Systems
The vulnerability affects Absolute Security’s Secure Access product versions earlier than 14.60. Users running any pre‑14.60 build of Secure Access are exposed.
Risk and Exploitability
The CVSS score of 8.7 highlights the high impact of this deficiency, while the EPSS score is currently unavailable, indicating no measured probability at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, unauthenticated traffic that targets the server’s connection initialization path. An attacker can exploit this weakness simply by sending malformed packets over the network; no credentials or local access are required, making the risk high for exposed installations.
OpenCVE Enrichment