Skip to content

Instantly share code, notes, and snippets.

@Delson704557
Last active September 16, 2022 04:18
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Delson704557/df06fcee0b2676d611aef799e1c4a0e6 to your computer and use it in GitHub Desktop.
Save Delson704557/df06fcee0b2676d611aef799e1c4a0e6 to your computer and use it in GitHub Desktop.
CVE-2022-40337
> [Description]
> OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2
> allows attackers to execute arbitrary code.
>
> ------------------------------------------
>
> [Additional Information]
> It is an authenticated attack.
>
> ------------------------------------------
>
> [VulnerabilityType Other]
> CWE-829: Inclusion of Functionality from Untrusted Control Sphere
>
> ------------------------------------------
>
> [Vendor of Product]
> Aspire Software
>
> ------------------------------------------
>
> [Affected Product Code Base]
> OASES Aviation MRO IT System - 8.8.0.2
>
> ------------------------------------------
>
> [Affected Component]
> menu function
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> Open print folder
>
> ------------------------------------------
>
> [Reference]
> https://www.aspiresoftware.com/companies/oases/
> https://oases.aero/
>
> ------------------------------------------
>
> [Discoverer]
> Delson Dsouza
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment