CVE-2022-40337
Description
OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated attackers can execute arbitrary code in OASES 8.8.0.2 via the Open Print Folder menu.
Vulnerability
OASES (Open Aviation Strategic Engineering System) version 8.8.0.2 allows authenticated attackers to execute arbitrary code via the Open Print Folder menu. The vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), indicating the software includes untrusted code from an external source [2]. The affected component is the menu function [2].
Exploitation
An attacker must have valid authentication credentials to the OASES system. By interacting with the Open Print Folder menu, the attacker can trigger arbitrary code execution. The exact steps are not detailed in public references, but the attack vector suggests providing a malicious file or folder path that leads to code execution [2].
Impact
Successful exploitation allows the attacker to execute arbitrary code with the privileges of the OASES application. This can lead to complete compromise of the system, including unauthorized access, data modification, or disruption of aircraft maintenance operations [1][2].
Mitigation
No official fix or patch has been released as of the available references. Users are advised to monitor the vendor's website [1] for updates. No workarounds are documented. The affected version is OASES 8.8.0.2.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- OASES/Open Aviation Strategic Engineering Systemdescription
- Range: = 8.8.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- gist.github.com/Delson704557/df06fcee0b2676d611aef799e1c4a0e6mitrex_refsource_MISC
- oases.aeromitrex_refsource_MISC
- www.aspiresoftware.com/companies/oases/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.