logo

OAS Engine Deep Dive: Abusing low-impact vulnerabilities to escalate privileges

ID: e957faae-f2b8-5319-8085-7f410136dbbc

STIX ID: report--e957faae-f2b8-5319-8085-7f410136dbbc

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-01-31

Date Updated: 2026-04-27

Author: Jared Rittle

...
...

Cisco Talos disclosed eight vulnerabilities in Open Automation Software's OAS Engine (patched in Version 19) that together allow attackers to bypass authentication (default config or replaying/stolen U_EP tokens), enumerate files, overwrite arbitrary files, and abuse unsanitized usernames to inject SSH public keys into the running configuration. The report includes protobuf protocol details for the OAS configuration protocol, step-by-step exploitation guidance showing how an attacker could gain SSH access as the OAS service user, and mitigation advice to upgrade and apply Snort rules to detect exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.