Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in Absolute Secure Access Leading to DoS

Absolute Secure Access contains multiple vulnerabilities that can be exploited by an attacker to trigger a Denial of Service condition, potentially disrupting service availability for users.

Absolute Software has disclosed multiple vulnerabilities affecting Absolute Secure Access, a suite commonly used for secure remote connectivity. These flaws allow an unauthenticated or authenticated attacker to trigger a Denial of Service (DoS) condition on the affected infrastructure. By successfully exploiting these vulnerabilities, an attacker can crash the application or exhaust system resources, leading to a loss of connectivity for remote users and potential operational disruption. The vulnerabilities affect the core components of the Absolute Secure Access platform. Organizations currently utilizing this product should prioritize reviewing vendor-provided security updates to mitigate service availability risks.

Impact

Successful exploitation of these vulnerabilities results in a Denial of Service, which directly impacts the availability of secure remote access services. For organizations relying on Absolute Secure Access, this could result in widespread loss of connectivity for remote workers and branch office staff. Depending on the deployment architecture, the impact could range from intermittent performance degradation to a complete outage of the secure gateway, potentially requiring manual intervention to restore service.

Recommendation

Prioritized actions for security and IT operations teams include:

  • Consult the Absolute Software security portal for the latest patches and firmware updates addressing these DoS vulnerabilities.
  • Implement service availability monitoring for Absolute Secure Access gateways to detect sudden spikes in resource utilization or service crashes.
  • Review network perimeter access policies to ensure that only authorized traffic can interact with the Absolute Secure Access gateway, reducing the surface area for remote DoS attempts.

Immediate actions

Review Absolute Software security updates for DoS patches

IT Operations 48h

Mitigations

Patch Absolute Secure Access to the version recommended by the vendor

immediate IT Operations

Multiple DoS vulnerabilities