First published: Thu Jun 01 2023(Updated: )
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System (CHS) | <3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28713 has a medium severity due to the risk of unauthorized access to plaintext stored passwords.
To fix CVE-2023-28713, upgrade to Contec CONPROSYS HMI System version 3.5.3 or later.
CVE-2023-28713 affects Contec CONPROSYS HMI System versions prior to 3.5.3.
The main risk with CVE-2023-28713 is that attackers can easily access user account information saved in plaintext.
There is no official workaround for CVE-2023-28713; updating the software is recommended for security.