[Japanese]

JVNDB-2022-002779

Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)

Overview

CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.

* OS Command Injection (CWE-78) - CVE-2022-44456
* Use of Default Credentials (CWE-1392) - CVE-2023-22331
* Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334
* Cross-site Scripting (CWE-79) - CVE-2023-22373
* Improper Access Control (CWE-284) - CVE-2023-22339

Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 10.0 (Critical) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
The above CVSS base scores have been assigned for CVE-2022-44456


CVSS V3 Severity:
"Base Metrics:7.5 (High) [Other]
"
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: High
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22331


CVSS V3 Severity:
Base Metrics:5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22334


CVSS V3 Severity:
Base Metrics:5.7 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22373


CVSS V3 Severity:
Base Metrics:7.5 (High) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22339
Affected Products


Contec
  • CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier - CVE-2022-44456
  • CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier - CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339

Impact

CVE-2022-44456
An arbitrary OS command may be executed on the server where the product is running, when an unauthenticated remote attacker sends a specially crafted request.

CVE-2023-22331
User credentials information may be altered by a remote unauthenticated attacker.

CVE-2023-22334
User credentials information may be obtained via a man-in-the-middle attack.

CVE-2023-22373
An arbitrary script may be executed on the web browser of the administrative user who is logging into the product, and sensitive information may be obtained.

CVE-2023-22339
A remote unauthenticated attacker may obtain the server certificate including the private key of the product.
Solution

[Update the software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

Contec
CWE (What is CWE?)

  1. OS Command Injection(CWE-78) [Other]
  2. Use of Password Hash Instead of Password for Authentication(CWE-836) [Other]
  3. Cross-site Scripting(CWE-79) [Other]
  4. Improper Access Control(CWE-284) [Other]
  5. Use of Default Credentials(CWE-1392) [Other]
CVE (What is CVE?)

  1. CVE-2022-44456
  2. CVE-2023-22331
  3. CVE-2023-22334
  4. CVE-2023-22373
  5. CVE-2023-22339
References

  1. JVN : JVNVU#96873821
  2. National Vulnerability Database (NVD) : CVE-2022-44456
  3. National Vulnerability Database (NVD) : CVE-2023-22331
  4. National Vulnerability Database (NVD) : CVE-2023-22334
  5. National Vulnerability Database (NVD) : CVE-2023-22339
  6. National Vulnerability Database (NVD) : CVE-2023-22373
  7. ICS-CERT ADVISORY : ICSA-22-347-03
Revision History

  • [2022/12/16]
      Web page was published
  • [2023/01/11]
      Title was modified
      Overview was modified
      CVSS Severity was modified
      Affected Products : Product version was modified
      Impact was modified
      Vendor Information : Content was modified
      CVE : CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339 was added
      CWE : CWE-1392, CWE-836, CWE-79, CWE-284 was added
  • [2024/05/29]
      References : Contents were added