HIGH🇵🇱 Wersja polska

CVE-2023-34353

CVSS 7.5v3.1pub. 2023-09-05upd. 2024-11-21

An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Openautomationsoftware Oas Platform

    APP
    Openautomationsoftware
    18.00.0072
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-26082CRITICAL9.1PL ✓same product

RCE poprzez zapis pliku w OAS Platform SecureTransferFiles

CVE-2022-26833CRITICAL9.4PL ✓same product

Brak uwierzytelnienia w REST API platformy OAS — nieautoryzowany dostęp

CVE-2023-34998HIGH8.1same product

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS ...

CVE-2023-31242HIGH8.1same product

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS ...

CVE-2022-26026HIGH7.5same product

A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation...