CVE-2024-11318

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the "/cgi-bin/ocap/" endpoint.
Configurations

No configuration.

History

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una vulnerabilidad IDOR (Insecure Direct Object Reference) en AbsysNet, que afecta a la versión 2.3.1. Esta vulnerabilidad podría permitir a un atacante remoto obtener la sesión de un usuario no autenticado mediante un ataque de fuerza bruta al identificador de sesión en el punto de conexión "/cgi-bin/ocap/".

18 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 14:15

Updated : 2024-11-18 17:11


NVD link : CVE-2024-11318

Mitre link : CVE-2024-11318

CVE.ORG link : CVE-2024-11318


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key