Record summary

CVE-2022-26833 has a selected CVSS score of 9.4 (critical); EIP currently links 1 Nuclei template.

Description

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheckV16.00.0121affected

Nuclei templates

1
ProjectDiscoveryCRITICALOpen Automation Software OAS Platform V16.00.0121 - Missing AuthenticationCVSS 9.4

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to the affected system.

Remediation

Apply the latest security patch or update to the Open Automation Software OAS Platform V16.00.0121 to fix the missing authentication issue.

WeaknessesCWE-306
Authorstrue13
Template tagscve2022cveoasossunauthopenautomationsoftwarevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CPE: cpe:2.3:a:openautomationsoftware:oas_platform:16.00.0112:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2