First published: Wed May 31 2023(Updated: )
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System (CHS) | <3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2758 has been categorized as a denial of service vulnerability, allowing attackers to deny user logins.
To mitigate CVE-2023-2758, upgrade the Contec CONPROSYS HMI System to version 3.5.3 or later.
CVE-2023-2758 affects Contec CONPROSYS HMI System versions 3.5.2 and earlier.
CVE-2023-2758 exploits time-zone mismatches in configuration files to create prolonged denial of service conditions for users.
Yes, CVE-2023-2758 can be exploited remotely by an unauthenticated attacker.