CVE-2026-55400
Received Received - Intake

Integer Underflow in Secure Access Server Causes DoS

Vulnerability report for CVE-2026-55400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: NetMotion Software

Description

CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
netmotion_software secure_access 14.57
netmotion_software secure_access to 14.57 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55400 is an integer underflow vulnerability in Secure Access servers running versions before 14.57. Authenticated attackers can exploit a non-default server configuration by sending specially crafted traffic, causing a persistent denial of service (DoS) condition. The flaw does not require user interaction and primarily impacts system availability.

Detection Guidance

Detecting this vulnerability requires checking the version of Secure Access servers. Use commands like 'show version' on the server or check the admin dashboard for the installed version. If the version is below 14.57, the system is vulnerable.

Impact Analysis

This vulnerability can lead to a persistent denial of service, meaning the affected server may become unavailable for extended periods. Since it requires an authenticated session, only users with access can exploit it. The impact is limited to availability, with no direct effect on confidentiality or integrity of data.

Compliance Impact

This vulnerability primarily impacts availability by causing a persistent denial of service, which could disrupt access to critical systems. While it does not directly affect confidentiality or integrity, prolonged downtime may lead to compliance violations under regulations like GDPR or HIPAA if it impairs access to protected data or systems.

Mitigation Strategies

Immediately update Secure Access servers to version 14.57 or later. Ensure no authenticated attackers can exploit non-default configurations by reviewing and hardening server settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart