PT-2024-16837 · Open Automation · Open Automation
Elcazator
·
Published
2024-12-03
·
Updated
2024-12-06
·
CVE-2024-11220
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open Automation Software versions prior to 20.00.0076
Description
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an
rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.Recommendations
For versions prior to 20.00.0076, upgrade to version 20.00.0076 or later to mitigate the risk of privilege escalation.
As a temporary workaround, consider restricting access to the
rdlx file and report execution functionality to minimize the risk of exploitation.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Automation