CVE-2023-34317
Open Automation Software vulnerability analysis and mitigation

Overview

An improper input validation vulnerability (CVE-2023-34317) exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. The vulnerability was discovered by Cisco Talos and publicly disclosed on September 5, 2023. The affected system is the OAS Platform, which is commonly found in industrial operations and enterprise environments, enabling communication between various devices including PLCs, servers, files, databases, and IoT platforms (Talos Report).

Technical details

The vulnerability exists in the OAS Engine's user creation functionality where no filtering is performed on username values. When adding a new user, a String protobuf can be leveraged as part of an authenticated request to specify the username. The vulnerability has been assigned a CVSS v3.1 score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. It is classified as CWE-20 (Improper Input Validation) (Talos Report).

Impact

When combined with authentication bypass vulnerabilities and the save configuration functionality, this vulnerability allows attackers to gain access to the underlying system by adding a user with the username field containing an SSH key. This could lead to unexpected data in the configuration and potential system compromise (SecurityWeek).

Exploitability

The vulnerability can be triggered by sending a specially crafted series of network requests. When combined with other authentication bypass vulnerabilities (CVE-2023-31242 and CVE-2023-34998), an attacker can gain unauthorized access to the system (Talos Blog).

Mitigation and workarounds

Access to the OAS Engine configuration server and its traffic should be restricted to exclusively those hosts authorized for configuration. The vulnerability has been fixed in version 19 of the OAS Platform, which can be downloaded from the vendor's website (Talos Report).

Additional resources


SourceThis report was generated using AI

Related Open Automation Software vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-34998HIGH8.1
  • Open Automation Software logoOpen Automation Software
  • cpe:2.3:a:openautomationsoftware:oas_platform
NoNoSep 05, 2023
CVE-2023-34353HIGH7.5
  • Open Automation Software logoOpen Automation Software
  • cpe:2.3:a:openautomationsoftware:oas_platform
NoNoSep 05, 2023
CVE-2023-34317MEDIUM6.5
  • Open Automation Software logoOpen Automation Software
  • cpe:2.3:a:openautomationsoftware:oas_platform
NoNoSep 05, 2023
CVE-2023-35124MEDIUM4.3
  • Open Automation Software logoOpen Automation Software
  • cpe:2.3:a:openautomationsoftware:oas_platform
NoNoSep 05, 2023
CVE-2023-34994MEDIUM4.3
  • Open Automation Software logoOpen Automation Software
  • cpe:2.3:a:openautomationsoftware:oas_platform
NoNoSep 05, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management