CVE-2023-28713: High severity contec conprosys hmi system (chs) vulnerability
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28713?
CVE-2023-28713 has a medium severity due to the risk of unauthorized access to plaintext stored passwords.
How do I fix CVE-2023-28713?
To fix CVE-2023-28713, upgrade to Contec CONPROSYS HMI System version 3.5.3 or later.
What systems are affected by CVE-2023-28713?
CVE-2023-28713 affects Contec CONPROSYS HMI System versions prior to 3.5.3.
What are the risks associated with CVE-2023-28713?
The main risk with CVE-2023-28713 is that attackers can easily access user account information saved in plaintext.
Is there a workaround for CVE-2023-28713?
There is no official workaround for CVE-2023-28713; updating the software is recommended for security.