HIGH🇵🇱 Wersja polska

CVE-2023-31242

CVSS 8.1v3.1pub. 2023-09-05upd. 2024-11-21

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openautomationsoftware Oas Platform

    APP
    Openautomationsoftware
    18.00.0072
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-26082CRITICAL9.1PL ✓same product

RCE poprzez zapis pliku w OAS Platform SecureTransferFiles

CVE-2022-26833CRITICAL9.4PL ✓same product

Brak uwierzytelnienia w REST API platformy OAS — nieautoryzowany dostęp

CVE-2023-34998HIGH8.1same product

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS ...

CVE-2023-34353HIGH7.5same product

An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automatio...

CVE-2022-26026HIGH7.5same product

A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation...