← Vulnerability feed

Vulnerability record · CVE-2023-34998 · published 5 September 2023

CVE-2023-34998: Openautomationsoftware oas platform cleartext transmission vulnerability

Openautomationsoftware · Oas Platform

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

8.1 CVSS 3.1 High EPSS 1.2% · top 33.1% CWE-319 · Cleartext transmissionCWE-287 · Improper authentication
8.1CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34998 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-31242Openautomationsoftware oas platform improper access control vulnerabilityAn authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-craft…EPSS 3.5%9.8CVE-2022-26082Openautomationsoftware oas platform missing authentication for critical function vulnerabilityA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A special…EPSS 20%9.4CVE-2022-26833Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-craft…EPSS 38%8.1CVE-2023-32615Openautomationsoftware oas platform vulnerabilityA file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially cra…EPSS 0.85%7.5CVE-2023-34353Openautomationsoftware oas platform vulnerabilityAn authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A …EPSS 1.2%7.5CVE-2022-26067Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.01…EPSS 1.3%7.5CVE-2022-26077Openautomationsoftware oas platform cleartext transmission vulnerabilityA cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automatio…EPSS 1.1%7.5CVE-2022-26303Openautomationsoftware oas platform missing authentication for critical function vulnerabilityAn external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2023-34998), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.