A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens omnivise T3000 Application Server |
|
CPEs | cpe:2.3:a:siemens:omnivise_t3000_application_server:r9.2:*:*:*:*:*:*:* | |
Vendors & Products |
Siemens
Siemens omnivise T3000 Application Server |
Tue, 13 Aug 2024 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in Omnivise T3000 Application Server (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system. | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system. |
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-08-02T10:36:19.439Z
Updated: 2024-08-13T07:54:14.901Z
Reserved: 2024-06-21T08:28:10.678Z
Link: CVE-2024-38878
Vulnrichment
Updated: 2024-08-02T14:00:37.845Z
NVD
Status : Analyzed
Published: 2024-08-02T11:16:42.260
Modified: 2024-09-17T15:50:41.117
Link: CVE-2024-38878
Redhat
No data.