Vulnerabilities > Contec

DATE CVE VULNERABILITY TITLE RISK
2023-05-23 CVE-2023-27514 OS Command Injection vulnerability in Contec Sv-Cpt-Mc310 Firmware and Sv-Cpt-Mc310F Firmware
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbitrary OS command.
network
low complexity
contec CWE-78
8.8
2023-05-23 CVE-2023-27518 Classic Buffer Overflow vulnerability in Contec Sv-Cpt-Mc310 Firmware and Sv-Cpt-Mc310F Firmware
Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute arbitrary code.
network
low complexity
contec CWE-120
8.8
2023-05-23 CVE-2023-27521 OS Command Injection vulnerability in Contec Sv-Cpt-Mc310 Firmware and Sv-Cpt-Mc310F Firmware
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command.
network
low complexity
contec CWE-78
8.8
2023-05-23 CVE-2023-27920 Unspecified vulnerability in Contec Sv-Cpt-Mc310 Firmware and Sv-Cpt-Mc310F Firmware
Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the affected product.
network
low complexity
contec
4.3
2023-05-23 CVE-2023-29919 Incorrect Default Permissions vulnerability in Contec Solarview Compact Firmware 6.0
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
network
low complexity
contec CWE-276
critical
9.1
2023-02-06 CVE-2023-23333 Command Injection vulnerability in Contec Solarview Compact Firmware 6.0
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
network
low complexity
contec CWE-77
critical
9.8
2023-01-30 CVE-2023-22324 SQL Injection vulnerability in Contec Conprosys HMI System
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command.
network
low complexity
contec CWE-89
6.5
2023-01-20 CVE-2023-22331 Improper Privilege Management vulnerability in Contec Conprosys HMI System
Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.
network
low complexity
contec CWE-269
7.5
2023-01-20 CVE-2023-22334 Improper Authentication vulnerability in Contec Conprosys HMI System
Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.
network
high complexity
contec CWE-287
5.3
2023-01-20 CVE-2023-22339 Unspecified vulnerability in Contec Conprosys HMI System
Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product.
network
low complexity
contec
7.5