Search Results (63 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97714 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97714 is a is a vulnerability in the authentication sub-system of Secure Access servers prior to version 14.60. Attackers can send a malformed response during authentication and cause a persistent denial of service.
CVE-2026-97715 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97715 is a vulnerability in the client registration process of Secure Access servers prior to version 14.60. Authenticated attackers can pass malformed data to the server and cause a persistent denial of service.
CVE-2026-97716 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97716 is a vulnerability in the connection set up sub-system of Secure Access servers prior to version 14.60. Unauthenticated attackers can send specially crafted traffic to the server and cause a persistent denial of service.
CVE-2026-97717 1 Absolute 1 Secure Access 2026-10-09 N/A
CVE-2026-97717 is a vulnerability in the proxy sub-system of Secure Access servers prior to 14.60. Authenticated attackers can send malformed data to the server and cause a persistent denial of service.
CVE-2026-55401 1 Absolute 1 Secure Access 2026-09-04 5.3 Medium
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
CVE-2026-55400 1 Absolute 1 Secure Access 2026-09-04 6.5 Medium
CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.
CVE-2026-55402 1 Absolute 1 Secure Access 2026-09-04 5.9 Medium
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
CVE-2026-40952 2 Absolute, Microsoft 2 Secure Access, Windows 2026-07-30 7.8 High
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
CVE-2026-40953 1 Absolute 1 Secure Access 2026-07-30 4.4 Medium
CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.
CVE-2026-40954 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
CVE-2026-40955 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
CVE-2026-40956 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.
CVE-2026-40957 1 Absolute 1 Secure Access 2026-07-30 7.5 High
o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
CVE-2026-40958 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
CVE-2026-33443 1 Absolute 1 Secure Access 2026-07-30 5.9 Medium
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
CVE-2026-33444 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
CVE-2026-33445 1 Absolute 1 Secure Access 2026-07-30 5.9 Medium
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
CVE-2026-55398 1 Absolute 1 Secure Access 2026-07-30 3.7 Low
CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
CVE-2026-55399 1 Absolute 1 Secure Access 2026-07-30 4.3 Medium
CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.
CVE-2026-40950 1 Absolute 1 Secure Access 2026-05-05 6.5 Medium
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service