Missing Authentication for Critical Function in OAS Platform - CVE-2022-26026
Published: May 26, 2022
OAS Platform
Open Automation Software
Description
The vulnerability allows a remote attacker can perform a denial of service (DoS) attack.
The vulnerability exists due to missing authentication for critical function in the OAS Engine SecureConfigValues functionality. A remote administrator can send a specially crafted request and cause a denial of service condition on the target system.