Authentication Vulnerability in CONPROSYS HMI System by Contec
CVE-2023-22334

5.3MEDIUM

Key Information:

Vendor
CVE Published:
20 January 2023

What is CVE-2023-22334?

The CONPROSYS HMI System is susceptible to a security vulnerability that allows remote authenticated attackers to gain unauthorized access to user credentials. This occurs due to the use of password hashes in place of actual passwords during authentication, making it feasible for attackers to initiate a man-in-the-middle attack and intercept user credentials. Users of CONPROSYS HMI System versions 3.4.5 and earlier are advised to review the security advisories and implement necessary safeguards to protect against this vulnerability.

Affected Version(s)

CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-22334 : Authentication Vulnerability in CONPROSYS HMI System by Contec