
Cloud Vulnerability DB
A community-led vulnerabilities database
An improper input validation vulnerability (CVE-2023-34317) exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. The vulnerability was discovered by Cisco Talos and publicly disclosed on September 5, 2023. The affected system is the OAS Platform, which is commonly found in industrial operations and enterprise environments, enabling communication between various devices including PLCs, servers, files, databases, and IoT platforms (Talos Report).
The vulnerability exists in the OAS Engine's user creation functionality where no filtering is performed on username values. When adding a new user, a String protobuf can be leveraged as part of an authenticated request to specify the username. The vulnerability has been assigned a CVSS v3.1 score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. It is classified as CWE-20 (Improper Input Validation) (Talos Report).
When combined with authentication bypass vulnerabilities and the save configuration functionality, this vulnerability allows attackers to gain access to the underlying system by adding a user with the username field containing an SSH key. This could lead to unexpected data in the configuration and potential system compromise (SecurityWeek).
The vulnerability can be triggered by sending a specially crafted series of network requests. When combined with other authentication bypass vulnerabilities (CVE-2023-31242 and CVE-2023-34998), an attacker can gain unauthorized access to the system (Talos Blog).
Access to the OAS Engine configuration server and its traffic should be restricted to exclusively those hosts authorized for configuration. The vulnerability has been fixed in version 19 of the OAS Platform, which can be downloaded from the vendor's website (Talos Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."