CVE-2024-11220
- EPSS 0.09%
- Veröffentlicht 06.12.2024 18:15:22
- Zuletzt bearbeitet 23.01.2025 16:54:24
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resu...
CVE-2024-27201
- EPSS 0.16%
- Veröffentlicht 03.04.2024 14:15:17
- Zuletzt bearbeitet 04.11.2025 19:17:03
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpected data in the configuration...
CVE-2024-24976
- EPSS 0.16%
- Veröffentlicht 03.04.2024 14:15:15
- Zuletzt bearbeitet 04.11.2025 19:16:58
A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the running program to stop. An att...
CVE-2024-22178
- EPSS 0.16%
- Veröffentlicht 03.04.2024 14:15:14
- Zuletzt bearbeitet 04.11.2025 19:16:31
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An at...
CVE-2024-21870
- EPSS 0.15%
- Veröffentlicht 03.04.2024 14:15:13
- Zuletzt bearbeitet 04.11.2025 19:16:30
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker ca...