A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
History

Fri, 06 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Openautomationsoftware
Openautomationsoftware oas Platform
CPEs cpe:2.3:a:openautomationsoftware:oas_platform:*:*:*:*:*:*:*:*
Vendors & Products Openautomationsoftware
Openautomationsoftware oas Platform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 18:00:00 +0000

Type Values Removed Values Added
Description A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
Title Open Automation Software Incorrect Execution-Assigned Permissions
Weaknesses CWE-279
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-12-06T17:45:51.853Z

Updated: 2024-12-06T20:43:08.930Z

Reserved: 2024-11-14T17:19:47.353Z

Link: CVE-2024-11220

cve-icon Vulnrichment

Updated: 2024-12-06T19:20:30.655Z

cve-icon NVD

Status : Received

Published: 2024-12-06T18:15:22.407

Modified: 2024-12-06T18:15:22.407

Link: CVE-2024-11220

cve-icon Redhat

No data.