OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.
History

Fri, 20 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Syscomgo
Syscomgo omflow
Weaknesses CWE-22
CPEs cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*
Vendors & Products Syscomgo
Syscomgo omflow

Mon, 16 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Description OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.
Title The SYSCOM Group OMFLOW - Arbitrary File Read
Weaknesses CWE-36
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-16T05:48:33.163Z

Updated: 2024-09-16T13:05:51.023Z

Reserved: 2024-09-13T09:43:47.413Z

Link: CVE-2024-8778

cve-icon Vulnrichment

Updated: 2024-09-16T13:05:45.855Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-16T06:15:11.777

Modified: 2024-09-20T14:23:37.697

Link: CVE-2024-8778

cve-icon Redhat

No data.