Open Automation Software Vulnerabilities and Affected Products
Vulnerabilities associated with Open Automation Software.
Products
Clear product- OAS Platform20 vulnerabilities
- Open Automation Software1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-11220HIGH | Open Automation Software Incorrect Execution-Assigned PermissionsA local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation. | CVSS8.5v4.0 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |