openautomationsoftware records
21 published records for vendor openautomationsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function7
- CWE-73 External Control of File Name or Path3
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-20 Improper Input Validation2
- CWE-284 Improper Access Control1
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2022-26833Proof of concept | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121.openautomationsoftware · oas platform · CWE-306 | Critical9.4 | — | 37.6% | May 25, 2022 |
45Plan | CVE-2022-26082No exploit | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112.openautomationsoftware · oas platform · CWE-306 | Critical9.8 | — | 20.1% | May 25, 2022 |
40Plan | CVE-2023-31242No exploit | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-284 | Critical9.8 | — | 3.5% | Sep 5, 2023 |
34Monitor | CVE-2024-11220No exploit | Open Automation Software Incorrect Execution-Assigned Permissionsopenautomationsoftware · open automation software · CWE-279 | High8.5 | — | 0.2% | Dec 6, 2024 |
32Monitor | CVE-2023-34998No exploit | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-319 | High8.1 | — | 1.2% | Sep 5, 2023 |
32Monitor | CVE-2023-32615No exploit | A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072.openautomationsoftware · oas platform · CWE-73 | High8.1 | — | 0.8% | Sep 5, 2023 |
31Monitor | CVE-2022-27169No exploit | An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16openautomationsoftware · oas platform · CWE-306 | High7.5 | — | 1.7% | May 25, 2022 |
30Monitor | CVE-2022-26067No exploit | An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform openautomationsoftware · oas platform · CWE-306 | High7.5 | — | 1.3% | May 25, 2022 |
30Monitor | CVE-2022-26303No exploit | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0openautomationsoftware · oas platform · CWE-306 | High7.5 | — | 1.3% | May 25, 2022 |
30Monitor | CVE-2022-26043No exploit | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform Vopenautomationsoftware · oas platform · CWE-306 | High7.5 | — | 1.3% | May 25, 2022 |
30Monitor | CVE-2023-34353No exploit | An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00openautomationsoftware · oas platform · CWE-330 | High7.5 | — | 1.2% | Sep 5, 2023 |
30Monitor | CVE-2022-26026No exploit | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.openautomationsoftware · oas platform · CWE-306 | High7.5 | — | 1.2% | May 25, 2022 |
30Monitor | CVE-2022-26077No exploit | A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open openautomationsoftware · oas platform · CWE-319 | High7.5 | — | 1.1% | May 25, 2022 |
26Monitor | CVE-2023-32271No exploit | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platopenautomationsoftware · oas platform · CWE-200 | Medium6.5 | — | 1.0% | Sep 5, 2023 |
26Monitor | CVE-2023-34317No exploit | An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18openautomationsoftware · oas platform · CWE-20 | Medium6.5 | — | 0.9% | Sep 5, 2023 |
19Monitor | CVE-2024-24976No exploit | A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platopenautomationsoftware · open automation software · CWE-130 | Medium4.9 | — | 0.9% | Apr 3, 2024 |
19Monitor | CVE-2024-21870No exploit | A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057.openautomationsoftware · open automation software · CWE-73 | Medium4.9 | — | 0.7% | Apr 3, 2024 |
19Monitor | CVE-2024-22178No exploit | A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0openautomationsoftware · open automation software · CWE-73 | Medium4.9 | — | 0.7% | Apr 3, 2024 |
19Monitor | CVE-2024-27201No exploit | An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platforopenautomationsoftware · open automation software · CWE-20 | Medium4.9 | — | 0.7% | Apr 3, 2024 |
17Monitor | CVE-2023-34994No exploit | An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAopenautomationsoftware · oas platform · CWE-770 | Medium4.3 | — | 0.8% | Sep 5, 2023 |
17Monitor | CVE-2023-35124No exploit | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platopenautomationsoftware · oas platform · CWE-209 | Medium4.3 | — | 0.6% | Sep 5, 2023 |
- CVE-2022-2683348Plan
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121.
CriticalCVSS 9.4Proof of conceptEPSS 38%openautomationsoftware · oas platformMay 25, 2022
- CVE-2022-2608245Plan
A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112.
CriticalCVSS 9.8No exploitEPSS 20%openautomationsoftware · oas platformMay 25, 2022
- CVE-2023-3124240Plan
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.
CriticalCVSS 9.8No exploitEPSS 3%openautomationsoftware · oas platformSep 5, 2023
- CVE-2024-1122034Monitor
Open Automation Software Incorrect Execution-Assigned Permissions
HighCVSS 8.5No exploitEPSS 0%openautomationsoftware · open automation softwareDec 6, 2024
- CVE-2023-3499832Monitor
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072.
HighCVSS 8.1No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2023-3261532Monitor
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072.
HighCVSS 8.1No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2022-2716931Monitor
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16
HighCVSS 7.5No exploitEPSS 2%openautomationsoftware · oas platformMay 25, 2022
- CVE-2022-2606730Monitor
An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformMay 25, 2022
- CVE-2022-2630330Monitor
An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.0
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformMay 25, 2022
- CVE-2022-2604330Monitor
An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformMay 25, 2022
- CVE-2023-3435330Monitor
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2022-2602630Monitor
A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformMay 25, 2022
- CVE-2022-2607730Monitor
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open
HighCVSS 7.5No exploitEPSS 1%openautomationsoftware · oas platformMay 25, 2022
- CVE-2023-3227126Monitor
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Plat
MediumCVSS 6.5No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2023-3431726Monitor
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18
MediumCVSS 6.5No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2024-2497619Monitor
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Plat
MediumCVSS 4.9No exploitEPSS 1%openautomationsoftware · open automation softwareApr 3, 2024
- CVE-2024-2187019Monitor
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057.
MediumCVSS 4.9No exploitEPSS 1%openautomationsoftware · open automation softwareApr 3, 2024
- CVE-2024-2217819Monitor
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0
MediumCVSS 4.9No exploitEPSS 1%openautomationsoftware · open automation softwareApr 3, 2024
- CVE-2024-2720119Monitor
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platfor
MediumCVSS 4.9No exploitEPSS 1%openautomationsoftware · open automation softwareApr 3, 2024
- CVE-2023-3499417Monitor
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OA
MediumCVSS 4.3No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023
- CVE-2023-3512417Monitor
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Plat
MediumCVSS 4.3No exploitEPSS 1%openautomationsoftware · oas platformSep 5, 2023