CVE-2023-34998
 
Severity Score
8.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.
Existe una vulnerabilidad de omisión de autenticación en la funcionalidad del motor OAS de Open Automation Software OAS Platform v18.00.0072. Una serie de solicitudes de red especialmente diseñadas pueden dar lugar a una autenticación arbitraria. Un atacante puede rastrear el tráfico de la red para desencadenar esta vulnerabilidad.
*Credits:
Discovered by a member of Cisco Talos.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-06-13 CVE Reserved
- 2023-09-05 CVE Published
- 2024-09-26 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1770 | Third Party Advisory | |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1770 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openautomationsoftware Search vendor "Openautomationsoftware" | Oas Platform Search vendor "Openautomationsoftware" for product "Oas Platform" | 18.00.0072 Search vendor "Openautomationsoftware" for product "Oas Platform" and version "18.00.0072" | - |
Affected
|