HIGH🇵🇱 Wersja polska

CVE-2023-28399

CVSS 7.8v3.1pub. 2023-06-01upd. 2025-01-09

Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the affected product is installed, therefore a wide range of privileges is permitted to a user of the PC where the affected product is installed. As a result, the user may be able to destroy the system and/or execute a malicious program.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Contec Conprosys Hmi System

    APP
    Contec
    < 3.5.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-44456CRITICAL9.8PL ✓same product

Command injection w CONPROSYS HMI System – zdalne wykonanie poleceń OS

CVE-2023-29154HIGH7.2same product

SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can a...

CVE-2023-28713HIGH8.1same product

Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account ...

CVE-2023-28657HIGH8.8same product

Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of ...

CVE-2023-22331HIGH7.5same product

Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote u...