CVE-2023-22334: Medium severity contec conprosys hmi system (chs) vulnerability
Published Jan 20, 2023
·Updated
Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.
Affected Software
2 affected components
Contec CONPROSYS HMI System<=3.4.5
Contec CONPROSYS HMI System (CHS): Ver.3.4.4 and prior
Remediation
Patch Available
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22334?
CVE-2023-22334 is considered a high severity vulnerability due to its potential for credential exposure.
2
How do I fix CVE-2023-22334?
To fix CVE-2023-22334, upgrade to version 3.4.6 or later of the CONPROSYS HMI System.
3
What systems are affected by CVE-2023-22334?
CVE-2023-22334 affects CONPROSYS HMI System (CHS) versions 3.4.5 and earlier.
4
Who can exploit CVE-2023-22334?
CVE-2023-22334 can be exploited by remote authenticated attackers through man-in-the-middle attacks.
5
What are the implications of CVE-2023-22334?
The implications of CVE-2023-22334 include unauthorized access to user credentials, leading to potential data breaches.