Executive brief
Absolute Security Secure Access, a solution used to provide secure remote connectivity for mobile workforces, is affected by a memory management flaw. An attacker with deep technical knowledge of the communication protocol could exploit this to temporarily crash the server. This would result in a denial-of-service, preventing legitimate users from connecting to corporate resources until the service is restored.
Technical details
A memory management vulnerability exists in Absolute Security (formerly NetMotion) Secure Access clients and servers prior to version 14.55. The flaw is located within the handling of the tunnel protocol. A remote attacker with intimate knowledge of and control over the tunnel protocol can trigger the vulnerability to cause a non-persistent denial-of-service (DoS) against the server. The vendor has assigned a CVSS 4.0 score of 6.9, noting that while the attack vector is network-based, it requires specific protocol manipulation. The issue is resolved in version 14.55.
Affected products
- Absolute Security (NetMotion) Secure Access prior to 14.55
Timeline
- 2026-07-15: advisory
- 2026-07-15: disclosed