An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.
VTP deterministic threat7.5of 100 · CVSS excluded
VTP analyst assessment
OAS Platform REST API authentication bypass
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence72%
Public exploitation · VTP factUNKNOWN
Assessment
Open Automation Software OAS Platform V16.00.0121 has an improper-authentication flaw in its REST API that can be triggered through a crafted sequence of HTTP requests, enabling unauthenticated API use. The supplied CVSS is 9.4, with high integrity and availability impact. No exploitation evidence is supplied.
Why it matters
Unauthenticated REST API use could permit consequential changes or service disruption.
The supplied attack vector is remote, low complexity, and requires no user interaction.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The affected-product CPE identifies 16.00.0112 while the description names V16.00.0121, creating a version-scope inconsistency.
Only one reference is counted, with no source text, KEV entry, assertions, or first-party telemetry supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Resolve the 16.00.0112 versus 16.00.0121 version discrepancy before scoping exposure.
AI baseline history (1)
BASELINE ASSESSED
OAS Platform REST API authentication bypassgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.38; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.