Impact
A frameable content flaw exists in the login page of Absolute Security Secure Access before version 14.55. The web application allows the login page to be embedded in an attacker‑controlled frame without proper frame‑busting headers or policy. When an administrator interacts with a malicious or compromised web site that frames the vulnerable login page, the credentials entered are captured by the attacker. This weakness, classified as CWE‑1021, permits the theft of authenticating credentials, potentially enabling privileged access to the protected environment.
Affected Systems
Absolute Security Secure Access servers running any version earlier than 14.55 are vulnerable. Administrators who log in to the vulnerable login page are at risk when they visit a malicious or compromised web site that frames the login page.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1% suggests a low current exploit likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to control a malicious website and for the target administrator to load the framed login page in a browser that does not enforce anti‑framing protections. Successful exploitation results in credential theft; it does not provide direct code execution or arbitrary system access, but the stolen credentials can be used for further compromise if additional safeguards are absent.
OpenCVE Enrichment