Vulnerabilidades em Contec Co., Ltd.

57 resultados
Análise Vexday

A Contec Co., Ltd. apresenta 24 vulnerabilidades catalogadas, com apenas 1 crítica, mas nenhuma sob exploração ativa no momento. A fraqueza predominante é injeção de comando (CWE-78), padrão que requer atenção em processos de validação de entrada. A ausência de publicações recentes sugere um cenário de risco estável, sem novos vetores de ataque identificados nos últimos 90 dias.

CVE-2022-35239—The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an inEPSS 1.4%CVE-2023-22324MEDIUMSQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbEPSS 1.3%CVE-2021-20656—Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtEPSS 1.2%CVE-2023-22339HIGHImproper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypassEPSS 1.1%CVE-2023-27512—Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8EPSS 1.0%CVE-2023-22331HIGHUse of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to altEPSS 1.0%CVE-2023-22334MEDIUMUse of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remotEPSS 0.9%CVE-2023-28657HIGHImproper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected prodEPSS 0.7%CVE-2026-82787HIGHMissing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product maEPSS 0.7%CVE-2026-82772HIGHBuffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web seEPSS 0.7%CVE-2026-82770HIGHBuffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's webEPSS 0.7%CVE-2023-28824MEDIUMServer-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected pEPSS 0.6%CVE-2026-82793HIGHUnrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a speciaEPSS 0.6%CVE-2026-82785MEDIUMStack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted requeEPSS 0.5%CVE-2026-82765HIGHPath traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitraryEPSS 0.5%CVE-2026-82768HIGHPath traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or alterEPSS 0.5%CVE-2026-82782MEDIUMOut-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attackEPSS 0.5%CVE-2026-82778MEDIUMAn exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may alloEPSS 0.4%CVE-2026-82775MEDIUMAn exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. AccesEPSS 0.4%CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%