CVE-2026-55402
Awaiting Analysis Awaiting Analysis - Queue

Out of Bounds Read in Secure Access Server

Vulnerability report for CVE-2026-55402, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-28

Assigner: NetMotion Software

Description

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-28
Generated
2026-09-03
AI Q&A
2026-08-13
EPSS Evaluated
2026-09-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
netmotion_software secure_access to 14.57 (exc)
netmotionsoftware secure_access to 14.57 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55402 is an out-of-bounds read vulnerability in Secure Access servers running versions before 14.57. Attackers with a man-in-the-middle position can exploit this by sending specially crafted data to the server, causing a persistent denial-of-service condition.

Detection Guidance

Detecting this vulnerability requires checking the version of Secure Access servers. Run 'show version' or 'get system status' on the server to verify if it is running a version prior to 14.57. Monitor network traffic for unusual patterns that may indicate a man-in-the-middle attack.

Impact Analysis

This vulnerability can lead to a persistent denial-of-service condition, making the server unavailable. It requires low attack complexity and no user interaction, meaning attackers can exploit it remotely with minimal effort.

Compliance Impact

This vulnerability primarily impacts availability by causing persistent denial-of-service conditions, which could disrupt access to critical systems. While it does not directly expose data, prolonged outages may interfere with compliance requirements for availability in standards like HIPAA or GDPR. However, the provided context does not specify direct impacts on data confidentiality or integrity.

Mitigation Strategies

Update Secure Access servers to version 14.57 or later to address the out-of-bounds read vulnerability and prevent persistent denial-of-service conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart