A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1951 | third party advisory exploit |