Memory Management Flaw in Absolute Secure Access Server
CVE-2025-49080
8.7HIGH
What is CVE-2025-49080?
A memory management vulnerability exists in Absolute Secure Access server versions 9.0 to 13.54, allowing remote attackers with network access to induce a Denial of Service by sending a specially crafted packet sequence. The attack is characterized by low complexity and does not require any specific privileges or user interaction, resulting in significant availability loss while not affecting confidentiality or integrity.
Affected Version(s)
Secure Access 9.0 < 13.54
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
