CVE-2022-26833
openautomationsoftware oas_platform Missing Authentication for Critical Function
Record summary
CVE-2022-26833 has a selected CVSS score of 9.4 (critical); EIP currently links 1 Nuclei template.
Description
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OAS PlatformBrowse Open Automation Software / OAS Platform | CVE List, VulnCheck | V16.00.0121 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALOpen Automation Software OAS Platform V16.00.0121 - Missing AuthenticationCVSS 9.4
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to the affected system.
Remediation
Apply the latest security patch or update to the Open Automation Software OAS Platform V16.00.0121 to fix the missing authentication issue.
Source: ProjectDiscovery