VYPR
Unrated severityNVD Advisory· Published Sep 16, 2022· Updated Aug 3, 2024

CVE-2022-40337

CVE-2022-40337

Description

OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated attackers can execute arbitrary code in OASES 8.8.0.2 via the Open Print Folder menu.

Vulnerability

OASES (Open Aviation Strategic Engineering System) version 8.8.0.2 allows authenticated attackers to execute arbitrary code via the Open Print Folder menu. The vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), indicating the software includes untrusted code from an external source [2]. The affected component is the menu function [2].

Exploitation

An attacker must have valid authentication credentials to the OASES system. By interacting with the Open Print Folder menu, the attacker can trigger arbitrary code execution. The exact steps are not detailed in public references, but the attack vector suggests providing a malicious file or folder path that leads to code execution [2].

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the OASES application. This can lead to complete compromise of the system, including unauthorized access, data modification, or disruption of aircraft maintenance operations [1][2].

Mitigation

No official fix or patch has been released as of the available references. Users are advised to monitor the vendor's website [1] for updates. No workarounds are documented. The affected version is OASES 8.8.0.2.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • OASES/Open Aviation Strategic Engineering Systemdescription
  • Range: = 8.8.0.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.