PatchSiren cyber security CVE debrief
CVE-2024-11220 Open Automation Software CVE debrief
A local privilege escalation vulnerability in Open Automation Software (OAS) allows authenticated low-level users to execute arbitrary code with SYSTEM privileges. The flaw exists in how OAS handles report files (.rdlx); a local attacker with credentials to running OAS services can create and execute a report containing malicious code that runs with elevated privileges. This vulnerability is rated HIGH severity (CVSS 7.8) and affects OAS versions prior to V20.00.0076. CISA published advisory ICSA-24-338-03 on December 3, 2024, coordinating disclosure. The vendor has released a patched version.
- Vendor
- Open Automation Software
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2024-12-03
- Advisory published
- 2024-12-03
- Advisory updated
- 2024-12-03
Who should care
Organizations running Open Automation Software in industrial control system environments, particularly those with multi-user server deployments where non-administrative users have OAS access. System administrators responsible for OAS deployments and security teams managing ICS/OT environments should prioritize patching.
Technical summary
The vulnerability stems from improper privilege handling when executing report files (.rdlx) in Open Automation Software. A local attacker with valid credentials to OAS services can create a malicious report file containing arbitrary code. When executed, this code runs with SYSTEM-level privileges rather than the attacker's original privilege level, enabling complete system compromise. The attack requires local access to the server machine and valid OAS credentials, but does not require user interaction. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects local attack vector, low complexity, low privileges required, no user interaction, and high impact across confidentiality, integrity, and availability.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Open Automation Software to version V20.00.0076 or later to address the privilege escalation vulnerability
- Restrict local access to OAS server systems to authorized administrators only
- Implement principle of least privilege for OAS service accounts
- Monitor for unauthorized .rdlx file creation or report execution on OAS servers
- Review and audit OAS user permissions to ensure minimal necessary access rights
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
Evidence notes
CISA CSAF advisory ICSA-24-338-03 identifies affected product as Open Automation Software versions prior to V20.00.0076. CVSS 3.1 vector confirms local attack vector with low attack complexity. Vendor fix confirmed in remediation section of source advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-11220 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-11220
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-11220 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11220
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.