Issue 187: RCE and API vulnerability in OAS platform, account takeover in Yunmai smart scale
Brief
This week, we have two API vulnerabilities: the first is a critical remote code execution (RCE) and API access flaw in the Open Automation Software (OAS) platform, the second a mass account takeover vulnerability in the Yunmai smart scale API. We also have an article on preventing API abuse, and a write-up on how to use pentesting methods to prevent API attacks on applications.
Vulnerability: OAS platform vulnerable to critical RCE and API access flaw
Bleeping Computer has featured news of a pair of vulnerabilities in the widely used Open Automation Software (OAS) platform . The OAS platform is a popular data connectivity platform used in industrial control systems, and it allows inter-operation between a wide range of devices and protocols.
