New vulnerabilities threaten another Solar Winds-style security disaster

Eight new vulnerabilities were recently discovered in the Open Automation Software (OAS) platform which, if leveraged, could have triggered another supply chain security disaster.

According to Talos, Cisco’s cybersecurity arm, the flaws include two high-severity vulnerabilities – CVE-2022-26833 (severity score 9.4) and CVE-2022-26082 (severity score 9.1) – which could enable threat actors to change the configuration of the platform to create new security groups and run arbitrary code.

Source