Open Automation Software's vulnerability portfolio concentrates in a niche but prominent industrial and enterprise automation platform where a relatively modest disclosure volume nevertheless skews toward critical severity. The platform's recurring exposure centers on authentication and access-control weaknesses—including missing authentication for critical functions, improper authentication mechanisms, and external control of file paths—alongside cleartext transmission of sensitive data, patterns endemic to legacy automation and SCADA-oriented software where modernization of security primitives lags deployment. Despite the serious nature of these findings, the vendor's disclosures have not attracted the broad exploitation attention typical of more widely exposed infrastructure. Defenders managing this platform should prioritize authentication and data-protection controls and treat critical advisories as urgent given the severity skew; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openautomationsoftware over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26833CRITICAL An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can | May 25, 2022 | 9.4 | 60 | NO | YES |
CVE-2022-26082CRITICAL A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network re | May 25, 2022 | 9.8 | 40 | NO | NO |
CVE-2023-31242CRITICAL An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests c | Sep 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-27169HIGH An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network re | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26303HIGH An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of ne | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26077HIGH A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00. | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26067HIGH An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26043HIGH An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series o | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26026HIGH A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network reques | May 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-34998HIGH An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests c | Sep 5, 2023 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openautomationsoftware.
Media articles that mention a CVE ID that affects a product developed by Openautomationsoftware — matched by CVE ID, not by vendor name.