Memory Management Flaw in Absolute Secure Access Server
CVE-2025-49080

8.7HIGH

Key Information:

Vendor
CVE Published:
12 June 2025

What is CVE-2025-49080?

A memory management vulnerability exists in Absolute Secure Access server versions 9.0 to 13.54, allowing remote attackers with network access to induce a Denial of Service by sending a specially crafted packet sequence. The attack is characterized by low complexity and does not require any specific privileges or user interaction, resulting in significant availability loss while not affecting confidentiality or integrity.

Affected Version(s)

Secure Access 9.0 < 13.54

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.