QID 376663
Date Published: 2022-06-15
QID 376663: Open Automation Software OAS Platform Improper Authentication Vulnerability
The OAS Platform offers data transport from any data source to any destination, while enabling data logging, data transformations, alarms and notifications, and cross-platform integration using SDKs for Windows, Linux, and Web applications.
A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.
Affected Versions:
Open Automation Software OAS Platform version 16.00.0121
QID Detection Logic (Authenticated):
Windows: QID will check the version of OAS Platform application and flag if vulnerable.
Successful exploitation of this vulnerability may allow an attacker to use unauthorized services.
Solution
Customers are advised to update to latest version Open Automation Software OAS Platform.
Vendor References
CVEs related to QID 376663
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Release Notes |
|