Vulnerabilities
Vulnerable Software
CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or a denial of service.
CVSS Score
2.3
EPSS Score
0.003
Published
2026-04-30
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or denial of service.
CVSS Score
2.3
EPSS Score
0.003
Published
2026-04-30
CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console.
CVSS Score
4.8
EPSS Score
0.001
Published
2026-01-17
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system.
CVSS Score
4.6
EPSS Score
0.001
Published
2026-01-17
CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash
CVSS Score
6.0
EPSS Score
0.003
Published
2026-01-17


Contact Us

Shodan ® - All rights reserved