QID 376664
Date Published: 2022-06-15
QID 376664: Open Automation Software OAS Platform Remote Code Execution (RCE) Vulnerability
The OAS Platform offers data transport from any data source to any destination, while enabling data logging, data transformations, alarms and notifications, and cross-platform integration using SDKs for Windows, Linux, and Web applications.
A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
Affected Versions:
Open Automation Software OAS Platform version 16.00.0112
QID Detection Logic (Authenticated):
Windows: QID will check the version of OAS Platform application and flag if vulnerable.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Customers are advised to update to latest version Open Automation Software OAS Platform.
Vendor References
CVEs related to QID 376664
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Release Notes |
|