A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.
History

Tue, 17 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens omnivise T3000 Application Server
CPEs cpe:2.3:a:siemens:omnivise_t3000_application_server:r9.2:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens omnivise T3000 Application Server

Tue, 13 Aug 2024 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Omnivise T3000 Application Server (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system. A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-08-02T10:36:19.439Z

Updated: 2024-08-13T07:54:14.901Z

Reserved: 2024-06-21T08:28:10.678Z

Link: CVE-2024-38878

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:37.845Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-02T11:16:42.260

Modified: 2024-09-17T15:50:41.117

Link: CVE-2024-38878

cve-icon Redhat

No data.