CVE-2025-49080 Details
Description
There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity.
A memory management vulnerability has been identified in Absolute Secure Access Server versions 9.0 prior to 13.54. This vulnerability allows attackers with network access to the server to cause a denial-of-service condition by sending a specially crafted sequence of packets. The attack is relatively simple to execute and does not require any special privileges or user interaction. While the vulnerability leads to a significant loss of availability, it does not impact the confidentiality or integrity of the system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-49080 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-762 | Mismatched Memory Management Routines | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| absolute secure access | >= 9.0, <= 13.54 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Jun 17, 2025 | CVE Modified | CISA-ADP |
| Jun 12, 2025 | New CVE Received | [email protected] |