PT-2024-9175 · Absysnet · Absysnet

Jordi Forès

·

Published

2024-11-18

·

Updated

2024-11-18

·

CVE-2024-11318

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AbsysNet version 2.3.1
Description: An IDOR (Insecure Direct Object Reference) vulnerability has been discovered, which could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the "/cgi-bin/ocap/" endpoint. This vulnerability is related to the bypass of authorization via the use of a user-controlled key. The exploitation of this vulnerability may allow a remote attacker to implement a brute-force attack.
Recommendations: For AbsysNet version 2.3.1, consider disabling access to the "/cgi-bin/ocap/" endpoint as a temporary workaround until a patch is available. Restricting access to this endpoint can minimize the risk of exploitation. Additionally, review logs for signs of exploit and patch the system as soon as possible.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2024-10862
CVE-2024-11318

Affected Products

Absysnet