Conprosys hmi system
This hub aggregates every CVE we track for Conprosys hmi system, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM6LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Conprosys hmi system.
- CVE-2025-34081CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug Info7.5
- CVE-2025-34080CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site Scripting6.1
- CVE-2023-28824Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may bypass the da...4.9
- CVE-2023-29154SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQ...7.2
- CVE-2023-28713Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can acces...8.1
- CVE-2023-28657Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As...8.8
- CVE-2023-28651Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege configures specially ...4.8
- CVE-2023-28399Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the ...7.8
- CVE-2023-2758Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service3.7
- CVE-2023-22324SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in th...6.5
- CVE-2023-22331Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.7.5
- CVE-2023-22373Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.5.4
- CVE-2023-22339Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate inc...7.5
- CVE-2023-22334Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials infor...5.3
- CVE-2022-44456CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafte...9.8
Product normalization is registry-driven with AI assist and human review. How it works