CVE-2024-11220

HIGH

Open Automation Software < 20.0.0.76 - Privilege Escalation via RDLX Report Execution

Title source: llm
STIX 2.1

Description

A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-279 CWE-732
Status published
Products (1)
openautomationsoftware/open_automation_software < 20.0.0.76
Published Dec 06, 2024
Tracked Since Feb 18, 2026