PT-2024-5341 · Omnivise · Omnivise T3000 Security Server+7
Published
2024-08-02
·
Updated
2024-09-20
·
CVE-2024-38877
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Omnivise T3000 Application Server R9.2 (All versions)
Omnivise T3000 Domain Controller R9.2 (All versions)
Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions)
Omnivise T3000 Product Data Management (PDM) R9.2 (All versions)
Omnivise T3000 R8.2 SP3 (All versions)
Omnivise T3000 R8.2 SP4 (All versions)
Omnivise T3000 Security Server R9.2 (All versions)
Omnivise T3000 Terminal Server R9.2 (All versions)
Omnivise T3000 Thin Client R9.2 (All versions)
Omnivise T3000 Whitelisting Server R9.2 (All versions)
Description
A vulnerability has been identified in the Omnivise T3000 components where initial system credentials are stored without sufficient protection. An attacker with remote shell access or physical access could retrieve the credentials, leading to confidentiality loss and allowing the attacker to laterally move within the affected network. The vulnerability is related to the storage of unencrypted credentials, which could enable an attacker to disclose protected information and elevate their privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omnivise T3000 Application Server
Omnivise T3000 Domain Controller
Omnivise T3000 Network Intrusion Detection System
Omnivise T3000 Product Data Management
Omnivise T3000 Security Server
Omnivise T3000 Terminal Server
Omnivise T3000 Thin Client
Omnivise T3000 Whitelisting Server