Записи openautomationsoftware
21 опубликованных записей вендора openautomationsoftware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-306 Missing Authentication for Critical Function7
- CWE-73 External Control of File Name or Path3
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-20 Improper Input Validation2
- CWE-284 Improper Access Control1
- CWE-330 Use of Insufficiently Random Values1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2022-26833Proof of concept | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121.openautomationsoftware · oas platform · CWE-306 | Критическая9,4 | — | 37,6 % | 25 мая 2022 г. |
45В плане | CVE-2022-26082Эксплойта нет | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112.openautomationsoftware · oas platform · CWE-306 | Критическая9,8 | — | 20,1 % | 25 мая 2022 г. |
40В плане | CVE-2023-31242Эксплойта нет | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-284 | Критическая9,8 | — | 3,5 % | 5 сент. 2023 г. |
34Наблюдать | CVE-2024-11220Эксплойта нет | Open Automation Software Incorrect Execution-Assigned Permissionsopenautomationsoftware · open automation software · CWE-279 | Высокая8,5 | — | 0,2 % | 6 дек. 2024 г. |
32Наблюдать | CVE-2023-34998Эксплойта нет | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-319 | Высокая8,1 | — | 1,2 % | 5 сент. 2023 г. |
32Наблюдать | CVE-2023-32615Эксплойта нет | A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-73 | Высокая8,1 | — | 0,8 % | 5 сент. 2023 г. |
31Наблюдать | CVE-2022-27169Эксплойта нет | An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16openautomationsoftware · oas platform · CWE-306 | Высокая7,5 | — | 1,7 % | 25 мая 2022 г. |
30Наблюдать | CVE-2022-26067Эксплойта нет | An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform openautomationsoftware · oas platform · CWE-306 | Высокая7,5 | — | 1,3 % | 25 мая 2022 г. |
30Наблюдать | CVE-2022-26303Эксплойта нет | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0openautomationsoftware · oas platform · CWE-306 | Высокая7,5 | — | 1,3 % | 25 мая 2022 г. |
30Наблюдать | CVE-2022-26043Эксплойта нет | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform Vopenautomationsoftware · oas platform · CWE-306 | Высокая7,5 | — | 1,3 % | 25 мая 2022 г. |
30Наблюдать | CVE-2023-34353Эксплойта нет | An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00openautomationsoftware · oas platform · CWE-330 | Высокая7,5 | — | 1,2 % | 5 сент. 2023 г. |
30Наблюдать | CVE-2022-26026Эксплойта нет | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.openautomationsoftware · oas platform · CWE-306 | Высокая7,5 | — | 1,2 % | 25 мая 2022 г. |
30Наблюдать | CVE-2022-26077Эксплойта нет | A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open openautomationsoftware · oas platform · CWE-319 | Высокая7,5 | — | 1,1 % | 25 мая 2022 г. |
26Наблюдать | CVE-2023-32271Эксплойта нет | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platopenautomationsoftware · oas platform · CWE-200 | Средняя6,5 | — | 1,0 % | 5 сент. 2023 г. |
26Наблюдать | CVE-2023-34317Эксплойта нет | An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18openautomationsoftware · oas platform · CWE-20 | Средняя6,5 | — | 0,9 % | 5 сент. 2023 г. |
19Наблюдать | CVE-2024-24976Эксплойта нет | A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platopenautomationsoftware · open automation software · CWE-130 | Средняя4,9 | — | 0,9 % | 3 апр. 2024 г. |
19Наблюдать | CVE-2024-21870Эксплойта нет | A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057.openautomationsoftware · open automation software · CWE-73 | Средняя4,9 | — | 0,7 % | 3 апр. 2024 г. |
19Наблюдать | CVE-2024-22178Эксплойта нет | A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0openautomationsoftware · open automation software · CWE-73 | Средняя4,9 | — | 0,7 % | 3 апр. 2024 г. |
19Наблюдать | CVE-2024-27201Эксплойта нет | An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platforopenautomationsoftware · open automation software · CWE-20 | Средняя4,9 | — | 0,7 % | 3 апр. 2024 г. |
17Наблюдать | CVE-2023-34994Эксплойта нет | An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAopenautomationsoftware · oas platform · CWE-770 | Средняя4,3 | — | 0,8 % | 5 сент. 2023 г. |
17Наблюдать | CVE-2023-35124Эксплойта нет | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platopenautomationsoftware · oas platform · CWE-209 | Средняя4,3 | — | 0,6 % | 5 сент. 2023 г. |
- CVE-2022-2683348В плане
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121.
КритическаяCVSS 9,4Proof of conceptEPSS 38 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2022-2608245В плане
A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112.
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2023-3124240В плане
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2024-1122034Наблюдать
Open Automation Software Incorrect Execution-Assigned Permissions
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %openautomationsoftware · open automation software6 дек. 2024 г.
- CVE-2023-3499832Наблюдать
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2023-3261532Наблюдать
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2022-2716931Наблюдать
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2022-2606730Наблюдать
An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2022-2630330Наблюдать
An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2022-2604330Наблюдать
An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2023-3435330Наблюдать
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2022-2602630Наблюдать
A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2022-2607730Наблюдать
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform25 мая 2022 г.
- CVE-2023-3227126Наблюдать
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Plat
СредняяCVSS 6,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2023-3431726Наблюдать
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18
СредняяCVSS 6,5Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2024-2497619Наблюдать
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Plat
СредняяCVSS 4,9Эксплойта нетEPSS 1 %openautomationsoftware · open automation software3 апр. 2024 г.
- CVE-2024-2187019Наблюдать
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %openautomationsoftware · open automation software3 апр. 2024 г.
- CVE-2024-2217819Наблюдать
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0
СредняяCVSS 4,9Эксплойта нетEPSS 1 %openautomationsoftware · open automation software3 апр. 2024 г.
- CVE-2024-2720119Наблюдать
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platfor
СредняяCVSS 4,9Эксплойта нетEPSS 1 %openautomationsoftware · open automation software3 апр. 2024 г.
- CVE-2023-3499417Наблюдать
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OA
СредняяCVSS 4,3Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.
- CVE-2023-3512417Наблюдать
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Plat
СредняяCVSS 4,3Эксплойта нетEPSS 1 %openautomationsoftware · oas platform5 сент. 2023 г.