CVE-2025-49080

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

23 Jun 2025, 14:09

Type Values Removed Values Added
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
First Time Absolute secure Access
Absolute
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49080 - () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49080 - Vendor Advisory

17 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-762

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de gestión de memoria en las versiones 9.0 a 13.54 del servidor Absolute Secure Access. Los atacantes con acceso de red al servidor pueden provocar una denegación de servicio (DPS) mediante el envío de una secuencia de paquetes especialmente manipulada. La complejidad del ataque es baja; no requiere requisitos de ataque, privilegios ni interacción del usuario. La pérdida de disponibilidad es alta; no afecta a la confidencialidad ni a la integridad.

12 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 17:15

Updated : 2025-06-23 14:09


NVD link : CVE-2025-49080

Mitre link : CVE-2025-49080

CVE.ORG link : CVE-2025-49080


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-762

Mismatched Memory Management Routines