First published: Mon Dec 19 2022(Updated: )
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System (CHS) | ||
Contec CONPROSYS HMI System (CHS) | <=3.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44456 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2022-44456, upgrade the CONPROSYS HMI System to version 3.4.5 or later.
CVE-2022-44456 affects users of Contec's CONPROSYS HMI System versions 3.4.4 and earlier.
CVE-2022-44456 allows remote unauthenticated attackers to execute arbitrary operating system commands on the affected server.
While the public details on active exploitation of CVE-2022-44456 are limited, the nature of the vulnerability suggests a risk of exploitation if not mitigated.