https://www.us-cert.gov/ics/advisories/icsa-20-140-02MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306
The affected components may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
IMPROPER OWNERSHIP MANAGEMENT CWE-282
Inadequate folder security permissions may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.
INADEQUATE ENCRYPTION STRENGTH CWE-326
Inadequate encryption may allow the passwords for OpenEnterprise user accounts to be obtained.