Executive brief
Absolute Security Secure Access servers (formerly NetMotion) are affected by a memory management flaw that can lead to a service outage. An attacker with access to the tunnel protocol can exploit this error to crash the server, resulting in a persistent denial-of-service. This would prevent legitimate users from securely accessing corporate resources until the system is recovered.
Technical details
A memory management error exists in the server component of Absolute Security Secure Access (formerly NetMotion) prior to version 14.55. The vulnerability is triggered by an attacker with low privileges who has control over the tunnel protocol. By manipulating protocol traffic, an attacker can induce a memory-related failure that results in a persistent denial-of-service (DoS) condition on the server. The issue is addressed in version 14.55. The CVSS 4.0 score of 7.1 reflects high availability impact with low attack complexity, though it requires a basic level of authentication/access to the tunnel.
Affected products
- Absolute Security (NetMotion) Secure Access prior to 14.55
Timeline
- 2026-07-15: advisory: NVD and vendor advisory published