First published: Fri Jan 20 2023(Updated: )
Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System | <=3.4.5 | |
Contec CONPROSYS HMI System (CHS): Ver.3.4.4 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22339 is an improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier, allowing a remote unauthenticated attacker to bypass access restrictions and obtain the server certificate, including the private key of the product.
CVE-2023-22339 has a high severity rating of 7.5, indicating it is a critical vulnerability that can be exploited remotely by an attacker to bypass access restrictions and obtain sensitive information.
CVE-2023-22339 affects CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier.
An attacker can exploit CVE-2023-22339 by sending specially crafted requests to the vulnerable CONPROSYS HMI System, bypassing access restrictions and obtaining the server certificate, including the private key.
Yes, it is recommended to update to a version of CONPROSYS HMI System that is not affected by the vulnerability, such as version 3.4.6 or later.