Lucene search

K
cveJpcertCVE-2022-44456
HistoryDec 19, 2022 - 3:15 a.m.

CVE-2022-44456

2022-12-1903:15:10
CWE-78
jpcert
web.nvd.nist.gov
48
cve-2022-44456
conprosys hmi system
chs
remote code execution
vulnerability
security
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.008

Percentile

81.5%

CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.

Affected configurations

Nvd
Vulners
Node
contecconprosys_hmi_systemRange3.4.4
VendorProductVersionCPE
contecconprosys_hmi_system*cpe:2.3:a:contec:conprosys_hmi_system:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Contec Co., Ltd.",
    "product": "CONPROSYS HMI System (CHS)",
    "versions": [
      {
        "version": "Ver.3.4.4?and earlier",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.008

Percentile

81.5%

Related for CVE-2022-44456