Vulnerability CVE-2024-38878


Published: 2024-08-02

Description:
A vulnerability has been identified in Omnivise T3000 Application Server (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Siemens Energy Omnivise T3000 8.2 SP3 Privilege Escalation / File Download
Andreas Kolbeck
14.11.2024

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://cert-portal.siemens.com/productcert/html/ssa-857368.html

Copyright 2024, cxsecurity.com

 

Back to Top