Impact
The vulnerability resides in the proxy sub‑system of Absolute Security’s Secure Access servers before version 14.60. An authenticated attacker can send malformed data that triggers a crash, resulting in a persistent denial‑of‑service state for all users of the affected server, thereby disrupting authentication services across the organization.
Affected Systems
Absolute Security’s Secure Access product, versions older than 14.60, is impacted. The advisory does not specify a patch version; therefore, any server with the cited build that permits authenticated access is at risk.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, but the EPSS score is unavailable, so exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of active exploitation. Because the attack requires authenticated credentials, compromised or privileged accounts must be present for exploitation.
OpenCVE Enrichment