Vulnerability CVE-2024-38876


Published: 2024-08-02

Description:
A vulnerability has been identified in Omnivise T3000 Application Server (All versions >= R9.2), Omnivise T3000 Domain Controller (All versions >= R9.2), Omnivise T3000 Product Data Management (PDM) (All versions >= R9.2), Omnivise T3000 Terminal Server (All versions >= R9.2), Omnivise T3000 Thin Client (All versions >= R9.2), Omnivise T3000 Whitelisting Server (All versions >= R9.2). The affected application regularly executes user modifiable code as a privileged user. This could allow a local authenticated attacker to execute arbitrary code with elevated privileges.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Siemens Energy Omnivise T3000 8.2 SP3 Privilege Escalation / File Download
Andreas Kolbeck
14.11.2024

Type:

CWE-552

(Files or Directories Accessible to External Parties)

 References:
https://cert-portal.siemens.com/productcert/html/ssa-857368.html

Copyright 2024, cxsecurity.com

 

Back to Top