PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-11220 Open Automation Software CVE debrief

A local privilege escalation vulnerability in Open Automation Software (OAS) allows authenticated low-level users to execute arbitrary code with SYSTEM privileges. The flaw exists in how OAS handles report files (.rdlx); a local attacker with credentials to running OAS services can create and execute a report containing malicious code that runs with elevated privileges. This vulnerability is rated HIGH severity (CVSS 7.8) and affects OAS versions prior to V20.00.0076. CISA published advisory ICSA-24-338-03 on December 3, 2024, coordinating disclosure. The vendor has released a patched version.

Vendor
Open Automation Software
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-03
Original CVE updated
2024-12-03
Advisory published
2024-12-03
Advisory updated
2024-12-03

Who should care

Organizations running Open Automation Software in industrial control system environments, particularly those with multi-user server deployments where non-administrative users have OAS access. System administrators responsible for OAS deployments and security teams managing ICS/OT environments should prioritize patching.

Technical summary

The vulnerability stems from improper privilege handling when executing report files (.rdlx) in Open Automation Software. A local attacker with valid credentials to OAS services can create a malicious report file containing arbitrary code. When executed, this code runs with SYSTEM-level privileges rather than the attacker's original privilege level, enabling complete system compromise. The attack requires local access to the server machine and valid OAS credentials, but does not require user interaction. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects local attack vector, low complexity, low privileges required, no user interaction, and high impact across confidentiality, integrity, and availability.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Open Automation Software to version V20.00.0076 or later to address the privilege escalation vulnerability
  • Restrict local access to OAS server systems to authorized administrators only
  • Implement principle of least privilege for OAS service accounts
  • Monitor for unauthorized .rdlx file creation or report execution on OAS servers
  • Review and audit OAS user permissions to ensure minimal necessary access rights
  • Apply defense-in-depth strategies for industrial control systems per CISA guidance

Evidence notes

CISA CSAF advisory ICSA-24-338-03 identifies affected product as Open Automation Software versions prior to V20.00.0076. CVSS 3.1 vector confirms local attack vector with low attack complexity. Vendor fix confirmed in remediation section of source advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-11220 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-11220

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-11220 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11220

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.