Threat analysts have uncovered vulnerabilities affecting the Open Automation Software (OAS) platform, leading to device access, denial of service, and remote code execution.
The OAS (Open Automation Software) platform is a widely used data connectivity solution, which unites industrial devices (PLC, OPC Modbus SCADA systems, IoT) network points, custom applications, custom APIs, as well as databases into a holistic system.

OAS is a stable solution for hardware and software connectivity that makes it easier to transfer data between proprietary devices and applications from multiple vendors and connects them to specific products.
OAS is used by large industrial companies,such as Michelin, Volvo, Intel, JBT AeroTech, Dart Oil and Gas and many others.
Like all companies, OAS has vulnerabilities in its platform that can pose the risk of disruption and disclosure of confidential information.
According to Cisco information, the new OAS version 16.00.0112 and newer are vulnerable to a series of high and critical severity vulnerabilities, which create the potential for repeated and harmful attacks.
So let's start with the most critical issue.CVE-2022-26833 has a severity rating of 9.4 out of 10, as it concerns unauthenticated access and the use of REST API functionality in OAS.
An attacker could exploit this weakness and send a series of HTTP requests to the vulnerable points.
As Cisco reports, the REST API is designed to provide programmatic access for configuration changes and data viewing to the “Default” user, whose identity the researchers were able to verify by sending a request with a blank username and password.
The second serious flaw is CVE-2022-26082 with a rating of 9.1 out of 10.This is a file write vulnerability module OAS Engine SecureTransferFiles
According to Cisco, a series of network requests sent to the vulnerable endpoint could lead to arbitrary remote code execution. This means that it allows a remote attacker to upload authorized_keys files to the .ssh directory of the oauser.

Cisco Talos has discovered several more flaws, all of which are categorized as high severity (CVSS:7.5). Let's take a look at some of them.
- CVE-2022-27169: obtain directory listing via network requests.
- CVE-2022-26077: information disclosure targeting account credentials
- CVE-2022-26026: denial of service and loss of data links
- CVE-2022-26303 and CVE-2022-26043: external configuration changes and creation of new users
Cisco provides mitigation advice for each of the above vulnerabilities, which includes disabling services and closing communication ports, so if upgrading to a newer version of OAS is impossible, there may be a workaround with some functionality or convenience trade-offs.
Otherwise, it is recommended to upgrade to a more recent version of the OAS platform. Security fixes for the two critical flaws described above appeared in version 16.00.0.113, which was released as a security update on May 22, 2022.
Upgrade delays are expected in industrial environments operating complex and intricate data connectivity systems, but in this case, due to the severity of the flaws revealed, it is important to take immediate action.
Information source: bleepingcomputer.com
