First published: Fri Jan 20 2023(Updated: )
Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System (CHS) | <=3.4.5 | |
Contec CONPROSYS HMI System (CHS) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22334 is considered a high severity vulnerability due to its potential for credential exposure.
To fix CVE-2023-22334, upgrade to version 3.4.6 or later of the CONPROSYS HMI System.
CVE-2023-22334 affects CONPROSYS HMI System (CHS) versions 3.4.5 and earlier.
CVE-2023-22334 can be exploited by remote authenticated attackers through man-in-the-middle attacks.
The implications of CVE-2023-22334 include unauthorized access to user credentials, leading to potential data breaches.