CVE-2023-28399: High severity contec conprosys hmi system (chs) vulnerability
Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the affected product is installed, therefore a wide range of privileges is permitted to a user of the PC where the affected product is installed. As a result, the user may be able to destroy the system and/or execute a malicious program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28399?
The severity of CVE-2023-28399 is classified as a critical vulnerability due to incorrect permission assignment.
How do I fix CVE-2023-28399?
To fix CVE-2023-28399, upgrade to CONPROSYS HMI System version 3.5.3 or later where the permission issue is resolved.
What software is affected by CVE-2023-28399?
CVE-2023-28399 affects CONPROSYS HMI System versions prior to 3.5.3.
What type of vulnerability is CVE-2023-28399?
CVE-2023-28399 is an access control vulnerability due to improper permission settings.
Who is the vendor for CVE-2023-28399?
The vendor for CVE-2023-28399 is Contec, which develops the CONPROSYS HMI System.