CVE-2022-44456: OS Command Injection
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44456?
CVE-2022-44456 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-44456?
To fix CVE-2022-44456, upgrade the CONPROSYS HMI System to version 3.4.5 or later.
Who is affected by CVE-2022-44456?
CVE-2022-44456 affects users of Contec's CONPROSYS HMI System versions 3.4.4 and earlier.
What type of attack does CVE-2022-44456 allow?
CVE-2022-44456 allows remote unauthenticated attackers to execute arbitrary operating system commands on the affected server.
Is CVE-2022-44456 being actively exploited?
While the public details on active exploitation of CVE-2022-44456 are limited, the nature of the vulnerability suggests a risk of exploitation if not mitigated.