CVE-2024-38876 Information

Description

A vulnerability has been identified in Omnivise T3000 Application Server (All versions >= R9.2) Omnivise T3000 Domain Controller (All versions >= R9.2) Omnivise T3000 Product Data Management (PDM) (All versions >= R9.2) Omnivise T3000 Terminal Server (All versions >= R9.2) Omnivise T3000 Thin Client (All versions >= R9.2) Omnivise T3000 Whitelisting Server (All versions >= R9.2). The affected application regularly executes user modifiable code as a privileged user. This could allow a local authenticated attacker to execute arbitrary code with elevated privileges.

Reference

https://cert-portal.siemens.com/productcert/html/ssa-857368.html

Share on: