VendorsOpen Automation Softwareopen_automation_softwareall versions
Vulnerabilities

Open Automation Software (OAS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-11220
Open Automation Software Incorrect Execution-Assigned Permissions
Published 2024-12-06 · Analyzed
8.5EPSS 0.002
CVE-2024-24976
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.
Published 2024-04-03 · Modified
4.9EPSS 0.009
CVE-2024-21870
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.
Published 2024-04-03 · Modified
4.9EPSS 0.007
CVE-2024-22178
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.
Published 2024-04-03 · Modified
4.9EPSS 0.007
CVE-2024-27201
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.
Published 2024-04-03 · Modified
4.9EPSS 0.007