[Japanese]
|
JVNDB-2022-002779
|
Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
|
CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
* OS Command Injection (CWE-78) - CVE-2022-44456
* Use of Default Credentials (CWE-1392) - CVE-2023-22331
* Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334
* Cross-site Scripting (CWE-79) - CVE-2023-22373
* Improper Access Control (CWE-284) - CVE-2023-22339
Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.
|
CVSS V3 Severity: Base Metrics 10.0 (Critical) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2022-44456
|
CVSS V3 Severity:
"Base Metrics:7.5 (High) [Other]"
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22331
|
CVSS V3 Severity:
Base Metrics:5.3 (Medium) [Other]
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22334
|
CVSS V3 Severity:
Base Metrics:5.7 (Medium) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22373
|
CVSS V3 Severity:
Base Metrics:7.5 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2023-22339
|
|
Contec
- CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier - CVE-2022-44456
- CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier - CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339
|
|
CVE-2022-44456
An arbitrary OS command may be executed on the server where the product is running, when an unauthenticated remote attacker sends a specially crafted request.
CVE-2023-22331
User credentials information may be altered by a remote unauthenticated attacker.
CVE-2023-22334
User credentials information may be obtained via a man-in-the-middle attack.
CVE-2023-22373
An arbitrary script may be executed on the web browser of the administrative user who is logging into the product, and sensitive information may be obtained.
CVE-2023-22339
A remote unauthenticated attacker may obtain the server certificate including the private key of the product.
|
[Update the software]
Update the software to the latest version according to the information provided by the developer.
|
Contec
|
- OS Command Injection(CWE-78) [Other]
- Use of Password Hash Instead of Password for Authentication(CWE-836) [Other]
- Cross-site Scripting(CWE-79) [Other]
- Improper Access Control(CWE-284) [Other]
- Use of Default Credentials(CWE-1392) [Other]
|
- CVE-2022-44456
- CVE-2023-22331
- CVE-2023-22334
- CVE-2023-22373
- CVE-2023-22339
|
- JVN : JVNVU#96873821
- National Vulnerability Database (NVD) : CVE-2022-44456
- National Vulnerability Database (NVD) : CVE-2023-22331
- National Vulnerability Database (NVD) : CVE-2023-22334
- National Vulnerability Database (NVD) : CVE-2023-22339
- National Vulnerability Database (NVD) : CVE-2023-22373
- ICS-CERT ADVISORY : ICSA-22-347-03
|
- [2022/12/16]
Web page was published
- [2023/01/11]
Title was modified
Overview was modified
CVSS Severity was modified
Affected Products : Product version was modified
Impact was modified
Vendor Information : Content was modified
CVE : CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339 was added
CWE : CWE-1392, CWE-836, CWE-79, CWE-284 was added
- [2024/05/29]
References : Contents were added
|