<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 05:05:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-226951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226951</link>
      <description>EUVD-2026-226951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226951</guid>
    </item>
    <item>
      <title>fkie_cve-2023-22331</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22331</link>
      <description>&lt;p&gt;Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-22331</guid>
    </item>
    <item>
      <title>GHSA-fh24-27cp-jr28</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fh24-27cp-jr28</link>
      <description>&lt;p&gt;Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fh24-27cp-jr28</guid>
    </item>
    <item>
      <title>gsd-2023-22331</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-22331</link>
      <description>gsd-2023-22331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-22331</guid>
    </item>
    <item>
      <title>ICSA-22-347-03 — Contec CONPROSYS HMI System (CHS)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-347-03</link>
      <description>&lt;p&gt;CONPROSYS HMI System versions 3.4.4 and prior are vulnerable to an OS Command Injection, which could allow an unauthenticated remote attacker to send specially crafted requests that could execute commands on the server. CVE-2022-44456 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). In CONPROSYS HMI System Ver.3.4.5 and prior, user credential information could be altered by a remote unauthenticated attacker. CVE-2023-22331 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, user credentials could be obtained via a machine-in-the-middle attack. CVE-2023-22334 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, an arbitrary script could be executed on the web browser of the administrative user logging into the product. This could result in sensitive information being obtained. CVE-2023-22373 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, a remote unauthenticated attacker could obtain the server certificate, including the private key of the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CONPROSYS HMI System versions 3.4.4 and prior are vulnerable to an OS Command Injection, which could allow an unauthenticated remote attacker to send specially crafted requests that could execute commands on the server. CVE-2022-44456 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). In CONPROSYS HMI System Ver.3.4.5 and prior, user credential information could be altered by a remote unauthenticated attacker. CVE-2023-22331 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, user credentials could be obtained via a machine-in-the-middle attack. CVE-2023-22334 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, an arbitrary script could be executed on the web browser of the administrative user logging into the product. This could result in sensitive information being obtained. CVE-2023-22373 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, a remote unauthenticated attacker could obtain the server certificate, including the private key of the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-347-03</guid>
    </item>
    <item>
      <title>jvndb-2022-002779</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2022-002779</link>
      <description>&lt;p&gt;CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&#13;
 &#13;
  * OS Command Injection (CWE-78) - CVE-2022-44456&#13;
  * Use of Default Credentials (CWE-1392) - CVE-2023-22331&#13;
  * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334&#13;
  * Cross-site Scripting (CWE-79) - CVE-2023-22373&#13;
  * Improper Access Control (CWE-284) - CVE-2023-22339&#13;
&#13;
Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&#13;
 &#13;
  * OS Command Injection (CWE-78) - CVE-2022-44456&#13;
  * Use of Default Credentials (CWE-1392) - CVE-2023-22331&#13;
  * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334&#13;
  * Cross-site Scripting (CWE-79) - CVE-2023-22373&#13;
  * Improper Access Control (CWE-284) - CVE-2023-22339&#13;
&#13;
Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2022-002779</guid>
    </item>
  </channel>
</rss>
