First published: Fri Jan 20 2023(Updated: )
Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System | <=3.4.5 | |
Contec CONPROSYS HMI System (CHS): Ver.3.4.4 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22331 is a vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier that allows a remote unauthenticated attacker to alter user credentials information.
CVE-2023-22331 has a severity score of 7.5, indicating a high severity.
CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier are affected by CVE-2023-22331.
To fix CVE-2023-22331, it is recommended to update CONPROSYS HMI System (CHS) to a version later than 3.4.5 that addresses the vulnerability.
More information about CVE-2023-22331 can be found at the following references: [https://jvn.jp/en/vu/JVNVU96873821](https://jvn.jp/en/vu/JVNVU96873821), [https://www.cisa.gov/uscert/ics/advisories/icsa-22-347-03](https://www.cisa.gov/uscert/ics/advisories/icsa-22-347-03), [https://www.contec.com/api/downloadlogger?download=/-/media/Contec/jp/support/security-info/contec_security_chs_230110_en.pdf](https://www.contec.com/api/downloadlogger?download=/-/media/Contec/jp/support/security-info/contec_security_chs_230110_en.pdf).