Openautomationsoftware
Openautomationsoftware OAS Platform: vulnerabilities and CVEs
Openautomationsoftware OAS Platform has 16 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs16
Last 12 months0
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35124 | Medium (4.3) | 0.63% | — | Sep 5, 2023 | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a… |
| CVE-2023-34998 | High (8.1) | 1.2% | — | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An… |
| CVE-2023-34994 | Medium (4.3) | 0.76% | — | Sep 5, 2023 | An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead… |
| CVE-2023-34353 | High (7.5) | 1.2% | — | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive… |
| CVE-2023-34317 | Medium (6.5) | 0.88% | — | Sep 5, 2023 | An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected… |
| CVE-2023-32615 | High (8.1) | 0.85% | — | Sep 5, 2023 | A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or… |
| CVE-2023-32271 | Medium (6.5) | 1.0% | — | Sep 5, 2023 | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a… |
| CVE-2023-31242 | Critical (9.8) | 3.5% | — | Sep 5, 2023 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An… |
| CVE-2022-27169 | High (7.5) | 1.7% | — | May 25, 2022 | An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of… |
| CVE-2022-26833 | Critical (9.4) | 38% | — | May 25, 2022 | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST… |
| CVE-2022-26303 | High (7.5) | 1.3% | — | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation… |
| CVE-2022-26082 | Critical (9.8) | 20% | — | May 25, 2022 | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code… |
| CVE-2022-26077 | High (7.5) | 1.1% | — | May 25, 2022 | A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing… |
| CVE-2022-26067 | High (7.5) | 1.3% | — | May 25, 2022 | An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to… |
| CVE-2022-26043 | High (7.5) | 1.3% | — | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the… |
| CVE-2022-26026 | High (7.5) | 1.2% | — | May 25, 2022 | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications.… |