<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 06:09:30 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-22334</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-22334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Contec Co., Ltd. CONPROSYS HMI System (CHS)&lt;/p&gt;
&lt;p&gt;Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Contec Co., Ltd. CONPROSYS HMI System (CHS)&lt;/p&gt;
&lt;p&gt;Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-22334</guid>
    </item>
    <item>
      <title>ICSA-22-347-03 — Contec CONPROSYS HMI System (CHS)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-347-03</link>
      <description>&lt;p&gt;CONPROSYS HMI System versions 3.4.4 and prior are vulnerable to an OS Command Injection, which could allow an unauthenticated remote attacker to send specially crafted requests that could execute commands on the server. CVE-2022-44456 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). In CONPROSYS HMI System Ver.3.4.5 and prior, user credential information could be altered by a remote unauthenticated attacker. CVE-2023-22331 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, user credentials could be obtained via a machine-in-the-middle attack. CVE-2023-22334 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, an arbitrary script could be executed on the web browser of the administrative user logging into the product. This could result in sensitive information being obtained. CVE-2023-22373 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, a remote unauthenticated attacker could obtain the server certificate, including the private key of the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CONPROSYS HMI System versions 3.4.4 and prior are vulnerable to an OS Command Injection, which could allow an unauthenticated remote attacker to send specially crafted requests that could execute commands on the server. CVE-2022-44456 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). In CONPROSYS HMI System Ver.3.4.5 and prior, user credential information could be altered by a remote unauthenticated attacker. CVE-2023-22331 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, user credentials could be obtained via a machine-in-the-middle attack. CVE-2023-22334 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, an arbitrary script could be executed on the web browser of the administrative user logging into the product. This could result in sensitive information being obtained. CVE-2023-22373 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, a remote unauthenticated attacker could obtain the server certificate, including the private key of the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-347-03</guid>
    </item>
  </channel>
</rss>
