Sploitus

CVE-2024-38878

3 known exploits for CVE-2024-38878

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.

Siemens Omnivise t3000 Application Server
= r9.2
CVSS 3.1
7.2 HIGH
EPSS
11.5% (96th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2024-08-02
CVE-2024-38878 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2024-38878

Proof-of-concept code and exploit modules indexed by Sploitus