Privileged Code Execution Vulnerability Affects Omnivise T3000 Products
CVE-2024-38876
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 2 August 2024
Summary
A vulnerability has been identified in various versions of Siemens Omnivise T3000 applications that permits the regular execution of user-modifiable code with privileged user access. This poses significant security risks, as it allows local authenticated attackers to leverage this flaw to execute arbitrary code with elevated privileges, potentially compromising the integrity and security of affected systems.
Affected Version(s)
Omnivise T3000 Application Server R9.2 0
Omnivise T3000 Domain Controller R9.2 0
Omnivise T3000 Product Data Management (PDM) R9.2 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published