The vendor explicitly identifies these products as affected by this CVE.
- Omnivise T3000 Application Server R9.2
- Omnivise T3000 Domain Controller R9.2
- Omnivise T3000 Product Data Management (PDM) R9.2
- Omnivise T3000 R8.2 SP3
- Omnivise T3000 R8.2 SP4
- Omnivise T3000 Terminal Server R9.2
- Omnivise T3000 Thin Client R9.2
- Omnivise T3000 Whitelisting Server R9.2
- Summary
- The affected application regularly executes user modifiable code as a privileged user. This could allow a local authenticated attacker to execute arbitrary code with elevated privileges.
- Remediation
- Install System Software Patch 22.173.20 and System Software Patch 22.173.52; apply additional mitigations from Omnivise T3000 Technical News 2024-089
