Security Advisory

CVE-2022-27169

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-05-25 20:15:29
Last updated 2025-04-15 19:00:46
Assigner talos
CVSS score 7.5
State PUBLISHED

Description

An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.