Executive brief
Absolute Security Secure Access (formerly NetMotion) is a VPN and secure connectivity client used by mobile workforces to maintain stable connections to corporate networks. A vulnerability in older versions of this software could allow a highly sophisticated attacker to view small amounts of random system memory. While the risk is low due to the complexity required for an exploit, it could potentially expose sensitive fragments of data handled by the device.
Technical details
A memory disclosure vulnerability exists in the Absolute Security (formerly NetMotion) Secure Access client. The flaw is triggered when an attacker possesses intimate knowledge of and total control over the tunnel protocol, enabling them to cause the client to leak small fragments of random memory. Exploitation requires high attack complexity and specific conditions, including user interaction and a man-in-the-middle or protocol-level compromise. The vulnerability is addressed in Secure Access client version 14.55.
Affected products
- Absolute Security (formerly NetMotion) Secure Access client versions prior to 14.55
Timeline
- 2026-07-15: advisory: NVD and vendor advisory published
- 2026-07-15: disclosed