← Vulnerability feed

Vulnerability record · CVE-2023-31242 · published 5 September 2023

CVE-2023-31242: Openautomationsoftware oas platform improper access control vulnerability

Openautomationsoftware · Oas Platform

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

9.8 CVSS 3.1 Critical EPSS 3.5% · top 11.3% CWE-284 · Improper access controlCWE-287 · Improper authentication
9.8CVSS 3.1 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1769 ExploitTechnical DescriptionThird Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1769 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1769 ExploitTechnical DescriptionThird Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1769 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2023-31242 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26082Openautomationsoftware oas platform missing authentication for critical function vulnerabilityA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A special…EPSS 20%9.4CVE-2022-26833Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-craft…EPSS 38%8.1CVE-2023-34998Openautomationsoftware oas platform cleartext transmission vulnerabilityAn authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially craft…EPSS 1.2%8.1CVE-2023-32615Openautomationsoftware oas platform vulnerabilityA file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially cra…EPSS 0.85%7.5CVE-2023-34353Openautomationsoftware oas platform vulnerabilityAn authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A …EPSS 1.2%7.5CVE-2022-26067Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.01…EPSS 1.3%7.5CVE-2022-26077Openautomationsoftware oas platform cleartext transmission vulnerabilityA cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automatio…EPSS 1.1%7.5CVE-2022-26303Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2023-31242), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.