CVE-2024-11318: Baratz Innovacion Absysnet

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the "/cgi-bin/ocap/" endpoint.

Affected products

Published 2024-11-18. Last modified 2026-06-17.