Search

Find a vulnerability

Search criteria

    19 vulnerabilities by Contec

    JVNDB-2026-032931

    Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-14 07:32
    Severity
    Summary
    Multiple vulnerabilities in Contec PC-HELPER series
    Details
    PC-HELPER series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
    • Cross-site scripting (CWE-79) - CVE-2026-82790
    • Cross-site request forgery (CWE-352) - CVE-2026-82764
    • OS command injection (CWE-78) - CVE-2026-82791
    • Cross-site scripting (CWE-79) - CVE-2026-82792
    • Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82793
    Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032931.html",
      "dc:date": "2026-09-14T16:32+09:00",
      "dcterms:issued": "2026-09-14T16:32+09:00",
      "dcterms:modified": "2026-09-14T16:32+09:00",
      "description": "PC-HELPER series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/434.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82790\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82791\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82792\u003c/li\u003e\u003cli\u003eUnrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82793\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032931.html",
      "sec:cpe": [
        {
          "#text": "cpe:/h:contec:can-2-usb",
          "@product": "CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-USB",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:can-2-wf",
          "@product": "CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-WF",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:dio-0404ry-lwf",
          "@product": "PC-HELPER Wireless I/O DIO-0404RY-LWF",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:dio-0404ry-lwf-us",
          "@product": "PC-HELPER Wireless I/O DIO-0404RY-LWF-US",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "5.4",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-032931",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU90314828/index.html",
          "@id": "JVNVU#90314828",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
          "@id": "CVE-2026-82764",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82790",
          "@id": "CVE-2026-82790",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82791",
          "@id": "CVE-2026-82791",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82792",
          "@id": "CVE-2026-82792",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82793",
          "@id": "CVE-2026-82793",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-352",
          "@title": "Cross-Site Request Forgery(CWE-352)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/434.html",
          "@id": "CWE-434",
          "@title": "Unrestricted Upload of File with Dangerous Type(CWE-434)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec PC-HELPER series"
    }

    JVNDB-2026-033234

    Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-15 03:40
    Severity
    Summary
    Multiple vulnerabilities in Contec FLEXLAN series
    Details
    FLEXLAN series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
    • OS command injection (CWE-78) - CVE-2026-82762, CVE-2026-82766
    • Cross-site scripting (CWE-79) - CVE-2026-82763, CVE-2026-82769, CVE-2026-82771
    • Cross-site request forgery (CWE-352) - CVE-2026-82764
    • Path traversal (CWE-23) - CVE-2026-82765, CVE-2026-82768
    • Cross-site scripting (CWE-79) - CVE-2026-82767
    • Buffer overflow (CWE-120) - CVE-2026-82770, CVE-2026-82772
    Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033234.html",
      "dc:date": "2026-09-15T12:40+09:00",
      "dcterms:issued": "2026-09-14T16:32+09:00",
      "dcterms:modified": "2026-09-15T12:40+09:00",
      "description": "FLEXLAN series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/23.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/120.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82762, CVE-2026-82766\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82763, CVE-2026-82769, CVE-2026-82771\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003ePath traversal (CWE-23) - CVE-2026-82765, CVE-2026-82768\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82767\u003c/li\u003e\u003cli\u003eBuffer overflow (CWE-120) - CVE-2026-82770, CVE-2026-82772\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033234.html",
      "sec:cpe": [
        {
          "#text": "cpe:/h:contec:ece1000",
          "@product": "ECE1000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:ece1020",
          "@product": "ECE1020",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:ecs1020",
          "@product": "ECS1020",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa3000",
          "@product": "FXA3000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa3000-",
          "@product": "FXA3000-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa3020",
          "@product": "FXA3020",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa3020-",
          "@product": "FXA3020-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa3200",
          "@product": "FXA3200",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa5000",
          "@product": "FXA5000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa5020",
          "@product": "FXA5020",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxa5020-",
          "@product": "FXA5020-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe3000",
          "@product": "FXE3000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe3000-",
          "@product": "FXE3000-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe3000-wp",
          "@product": "FXE3000-WP",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe4000",
          "@product": "FXE4000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe4000-wp",
          "@product": "FXE4000-WP",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe5000",
          "@product": "FXE5000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxe5000-",
          "@product": "FXE5000-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxs300_-cn",
          "@product": "FXS300[]-CN",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxs4000",
          "@product": "FXS4000",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxs4020",
          "@product": "FXS4020",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxs5000-",
          "@product": "FXS5000-[][]",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:fxs5021",
          "@product": "FXS5021",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:rp-wah-sr1",
          "@product": "RP-WAH-SR1",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:rp-wah-sr12",
          "@product": "RP-WAH-SR12",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:rp-wah-sr2",
          "@product": "RP-WAH-SR2",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:rp-wah-sr22",
          "@product": "RP-WAH-SR22",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:sga1000",
          "@product": "SGA1000",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-033234",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU99009004/index.html",
          "@id": "JVNVU#99009004",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82762",
          "@id": "CVE-2026-82762",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82763",
          "@id": "CVE-2026-82763",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
          "@id": "CVE-2026-82764",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82765",
          "@id": "CVE-2026-82765",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82766",
          "@id": "CVE-2026-82766",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82767",
          "@id": "CVE-2026-82767",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82768",
          "@id": "CVE-2026-82768",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82769",
          "@id": "CVE-2026-82769",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82770",
          "@id": "CVE-2026-82770",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82771",
          "@id": "CVE-2026-82771",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82772",
          "@id": "CVE-2026-82772",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/120.html",
          "@id": "CWE-120",
          "@title": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)(CWE-120)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/23.html",
          "@id": "CWE-23",
          "@title": "Relative Path Traversal(CWE-23)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-352",
          "@title": "Cross-Site Request Forgery(CWE-352)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec FLEXLAN series"
    }

    JVNDB-2026-032930

    Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-14 07:32
    Severity
    Summary
    Multiple vulnerabilities in SolarView Compact
    Details
    SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
    • OS command injection in Schedule Settings (CWE-78) - CVE-2026-82794
    • Cross-site scripting in Schedule Settings and Mail Send Setting (CWE-79) - CVE-2026-82795
    • Cross-site scripting in Image Management (CWE-79) - CVE-2026-82796
    Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032930.html",
      "dc:date": "2026-09-14T16:32+09:00",
      "dcterms:issued": "2026-09-14T16:32+09:00",
      "dcterms:modified": "2026-09-14T16:32+09:00",
      "description": "SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOS command injection in Schedule Settings (CWE-78) - CVE-2026-82794\u003c/li\u003e\u003cli\u003eCross-site scripting in Schedule Settings and Mail Send Setting (CWE-79) - CVE-2026-82795\u003c/li\u003e\u003cli\u003eCross-site scripting in Image Management (CWE-79) - CVE-2026-82796\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032930.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
          "@product": "SolarView Compact SV-CPT-MC310F",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
          "@product": "SolarView Compact SV-CPT-MC310",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-032930",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU97753461/index.html",
          "@id": "JVNVU#97753461",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82794",
          "@id": "CVE-2026-82794",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82795",
          "@id": "CVE-2026-82795",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82796",
          "@id": "CVE-2026-82796",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Multiple vulnerabilities in SolarView Compact"
    }

    JVNDB-2026-033235

    Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-29 03:18
    Severity
    Summary
    Multiple vulnerabilities in Contec CONPROSYS series
    Details
    CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
    • Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788
    • OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779
    • Exposure of information through directory listing (CWE-548) - CVE-2026-82775, CVE-2026-82778
    • Dependency on vulnerable third-party component (CWE-1395)
      • This issue is caused by a vulnerability in chart.js (CVE-2020-7746).
    • Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82780
    • Cross-site scripting (CWE-79) - CVE-2026-82781
    • Out-of-bounds write (CWE-787) - CVE-2026-82782
    • Cross-site request forgery (CWE-352) - CVE-2026-82764
    • Plaintext storage of a password (CWE-256) - CVE-2026-82783
    • Missing authentication for critical function (CWE-306) - CVE-2026-82784
    • Stack-based buffer overflow (CWE-121) - CVE-2026-82785
    • Insufficiently protected credentials (CWE-522) - CVE-2026-82786
    • Missing authentication for critical function (CWE-306) - CVE-2026-82787
    • Eval injection (CWE-95) - CVE-2026-82789
    Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
    References
    JVN https://jvn.jp/en/vu/JVNVU96551518/index.html
    CVE https://www.cve.org/CVERecord?id=CVE-2020-7746
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82764
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82773
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82774
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82775
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82776
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82777
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82778
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82779
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82780
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82781
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82782
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82783
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82784
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82785
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82786
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82787
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82788
    CVE https://www.cve.org/CVERecord?id=CVE-2026-82789
    Stack-based Buffer Overflow(CWE-121) https://cwe.mitre.org/data/definitions/121.html
    Dependency on Vulnerable Third-Party Component(CWE-1395) https://cwe.mitre.org/data/definitions/1395.html
    Unprotected Storage of Credentials(CWE-256) https://cwe.mitre.org/data/definitions/256.html
    Missing Authentication for Critical Function(CWE-306) https://cwe.mitre.org/data/definitions/306.html
    Cross-Site Request Forgery(CWE-352) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Unrestricted Upload of File with Dangerous Type(CWE-434) https://cwe.mitre.org/data/definitions/434.html
    Insufficiently Protected Credentials(CWE-522) https://cwe.mitre.org/data/definitions/522.html
    Exposure of Information Through Directory Listing(CWE-548) https://cwe.mitre.org/data/definitions/548.html
    OS Command Injection(CWE-78) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Out-of-bounds Write(CWE-787) https://cwe.mitre.org/data/definitions/787.html
    Cross-site Scripting(CWE-79) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')(CWE-95) https://cwe.mitre.org/data/definitions/95.html
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033235.html",
      "dc:date": "2026-09-29T12:18+09:00",
      "dcterms:issued": "2026-09-14T16:32+09:00",
      "dcterms:modified": "2026-09-29T12:18+09:00",
      "description": "CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/548.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/1395.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2020-7746\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/434.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/787.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/256.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/121.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/522.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/95.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788\u003c/li\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779\u003c/li\u003e\u003cli\u003eExposure of information through directory listing (CWE-548) - CVE-2026-82775, CVE-2026-82778\u003c/li\u003e\u003cli\u003eDependency on vulnerable third-party component (CWE-1395)\u003c/li\u003e\u003cul\u003e\u003cli\u003eThis issue is caused by a vulnerability in chart.js (CVE-2020-7746).\u003c/li\u003e\u003c/ul\u003e\u003cli\u003eUnrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82780\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82781\u003c/li\u003e\u003cli\u003eOut-of-bounds write (CWE-787) - CVE-2026-82782\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003ePlaintext storage of a password (CWE-256) - CVE-2026-82783\u003c/li\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-82784\u003c/li\u003e\u003cli\u003eStack-based buffer overflow (CWE-121) - CVE-2026-82785\u003c/li\u003e\u003cli\u003eInsufficiently protected credentials (CWE-522) - CVE-2026-82786\u003c/li\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-82787\u003c/li\u003e\u003cli\u003eEval injection (CWE-95) - CVE-2026-82789\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033235.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:contec:conprosys_hmi_system",
          "@product": "CONPROSYS HMI System (CHS)",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:configurable_type_cps-pcs341_-ds1-120",
          "@product": "Configurable type CPS-PCS341[][]-DS1-1201",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cps-tm341g5mb-adsc1-931",
          "@product": "CPS-TM341G5MB-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cps-tm341gmb-adsc1-931",
          "@product": "CPS-TM341GMB-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cps-tm341mb-adsc1-931",
          "@product": "CPS-TM341MB-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cpsl-08p1en",
          "@product": "CPSL-08P1EN",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cpsn-eob471ei-",
          "@product": "Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cpsn-mcb271-",
          "@product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:cpsn-pcb271-s1-041",
          "@product": "Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:integrated_type_cps-pc341_-9201",
          "@product": "Integrated Type CPS-PC341[][]-*-9201",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:m2m_controller_configurable_type_cps-mcs341",
          "@product": "M2M Controller Configurable type CPS-MCS341*",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:m2m_controller_integrated_type_cps-mc341",
          "@product": "M2M Controller Integrated Type CPS-MC341",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:m2m_gateway_configurable_type_cps-mgs341",
          "@product": "M2M Gateway Configurable type CPS-MGS341*",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:contec:m2m_gateway_integrated_type_cps-mg341",
          "@product": "M2M Gateway Integrated Type CPS-MG341*",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "6.1",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-033235",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU96551518/index.html",
          "@id": "JVNVU#96551518",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2020-7746",
          "@id": "CVE-2020-7746",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
          "@id": "CVE-2026-82764",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82773",
          "@id": "CVE-2026-82773",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82774",
          "@id": "CVE-2026-82774",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82775",
          "@id": "CVE-2026-82775",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82776",
          "@id": "CVE-2026-82776",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82777",
          "@id": "CVE-2026-82777",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82778",
          "@id": "CVE-2026-82778",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82779",
          "@id": "CVE-2026-82779",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82780",
          "@id": "CVE-2026-82780",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82781",
          "@id": "CVE-2026-82781",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82782",
          "@id": "CVE-2026-82782",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82783",
          "@id": "CVE-2026-82783",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82784",
          "@id": "CVE-2026-82784",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82785",
          "@id": "CVE-2026-82785",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82786",
          "@id": "CVE-2026-82786",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82787",
          "@id": "CVE-2026-82787",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82788",
          "@id": "CVE-2026-82788",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-82789",
          "@id": "CVE-2026-82789",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/121.html",
          "@id": "CWE-121",
          "@title": "Stack-based Buffer Overflow(CWE-121)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/1395.html",
          "@id": "CWE-1395",
          "@title": "Dependency on Vulnerable Third-Party Component(CWE-1395)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/256.html",
          "@id": "CWE-256",
          "@title": "Unprotected Storage of Credentials(CWE-256)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/306.html",
          "@id": "CWE-306",
          "@title": "Missing Authentication for Critical Function(CWE-306)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-352",
          "@title": "Cross-Site Request Forgery(CWE-352)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/434.html",
          "@id": "CWE-434",
          "@title": "Unrestricted Upload of File with Dangerous Type(CWE-434)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/522.html",
          "@id": "CWE-522",
          "@title": "Insufficiently Protected Credentials(CWE-522)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/548.html",
          "@id": "CWE-548",
          "@title": "Exposure of Information Through Directory Listing(CWE-548)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/787.html",
          "@id": "CWE-787",
          "@title": "Out-of-bounds Write(CWE-787)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/95.html",
          "@id": "CWE-95",
          "@title": "Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)(CWE-95)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec CONPROSYS series"
    }

    JVNDB-2025-007754

    Vulnerability from jvndb - Published: 2025-07-02 02:31 - Updated:2025-07-02 02:31
    Severity
    Summary
    Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
    Details
    CONPROSYS HMI System (CHS) provided by Contec Co.,Ltd. contains multiple vulnerabilities listed below. * Reflected cross-site scripting (CWE-79) - CVE-2025-34080 * Insertion of sensitive information into debugging code (CWE-215) - CVE-2025-34081 Alex Williams of Converge Technology Solutions reported these vulnerabilities to Vulncheck Inc., and Vulncheck Inc. reported these vulnerabilities to the developer. Based on the coordination request made by the developer, JPCERT/CC coordinated with Vulncheck Inc. and the developer.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-007754.html",
      "dc:date": "2025-07-02T11:31+09:00",
      "dcterms:issued": "2025-07-02T11:31+09:00",
      "dcterms:modified": "2025-07-02T11:31+09:00",
      "description": "CONPROSYS HMI System (CHS) provided by Contec Co.,Ltd. contains multiple vulnerabilities listed below.\r\n\r\n  * Reflected cross-site scripting (CWE-79) - CVE-2025-34080\r\n  * Insertion of sensitive information into debugging code (CWE-215) - CVE-2025-34081\r\n\r\nAlex Williams of Converge Technology Solutions reported these vulnerabilities to Vulncheck Inc., and\r\nVulncheck Inc. reported these vulnerabilities to the developer.\r\nBased on the coordination request made by the developer, JPCERT/CC coordinated with Vulncheck Inc. and the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-007754.html",
      "sec:cpe": {
        "#text": "cpe:/a:contec:conprosys_hmi_system",
        "@product": "CONPROSYS HMI System (CHS)",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "6.1",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-007754",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU92266386/index.html",
          "@id": "JVNVU#92266386",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-34080",
          "@id": "CVE-2025-34080",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-34081",
          "@id": "CVE-2025-34081",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/215.html",
          "@id": "CWE-215",
          "@title": "Insertion of Sensitive Information Into Debugging Code(CWE-215)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
    }

    JVNDB-2023-002002

    Vulnerability from jvndb - Published: 2023-06-01 04:48 - Updated:2024-03-19 09:13
    Severity
    Summary
    Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
    Details
    CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below. * Plaintext storage of a password (CWE-256) - CVE-2023-28713 * Incorrect permission assignment for critical resource (CWE-732) - CVE-2023-28399 * Improper access control (CWE-284) - CVE-2023-28657 * Cross-site scripting (CWE-79) - CVE-2023-28651 * Server-side request forgery (CWE-918)- CVE-2023-28824 * SQL injection (CWE-89) - CVE-2023-29154 * Improper control of interaction frequency (CWE-799) - CVE-2023-2758 Michael Heinzl reported the vulnerabilities listed below to JPCERT/CC, and JPCERT/CC coordinated with the developer. CVE-2023-28713, CVE-2023-28399, CVE-2023-28657, CVE-2023-28651, CVE-2023-28824, CVE-2023-29154 Tenable, Inc. reported CVE-2023-2758 vulnerability to the developer, and based on the coordination request made by the developer, JPCERT/CC coordinated with Tenable, Inc. and the developer.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-002002.html",
      "dc:date": "2024-03-19T18:13+09:00",
      "dcterms:issued": "2023-06-01T13:48+09:00",
      "dcterms:modified": "2024-03-19T18:13+09:00",
      "description": "CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n\r\n* Plaintext storage of a password (CWE-256) - CVE-2023-28713\r\n* Incorrect permission assignment for critical resource (CWE-732) - CVE-2023-28399\r\n* Improper access control (CWE-284) - CVE-2023-28657\r\n* Cross-site scripting (CWE-79) - CVE-2023-28651\r\n* Server-side request forgery (CWE-918)- CVE-2023-28824\r\n* SQL injection (CWE-89) - CVE-2023-29154\r\n* Improper control of interaction frequency (CWE-799) - CVE-2023-2758\r\n\r\nMichael Heinzl reported the vulnerabilities listed below to JPCERT/CC, and JPCERT/CC coordinated with the developer.\r\nCVE-2023-28713, CVE-2023-28399, CVE-2023-28657, CVE-2023-28651, CVE-2023-28824, CVE-2023-29154\r\n\r\nTenable, Inc. reported CVE-2023-2758 vulnerability to the developer, and based on the coordination request made by the developer, JPCERT/CC coordinated with Tenable, Inc. and the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-002002.html",
      "sec:cpe": {
        "#text": "cpe:/a:contec:conprosys_hmi_system",
        "@product": "CONPROSYS HMI System (CHS)",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2023-002002",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU93372935/index.html",
          "@id": "JVNVU#93372935",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-28713",
          "@id": "CVE-2023-28713",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-28399",
          "@id": "CVE-2023-28399",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-28657",
          "@id": "CVE-2023-28657",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-28651",
          "@id": "CVE-2023-28651",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-28824",
          "@id": "CVE-2023-28824",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-29154",
          "@id": "CVE-2023-29154",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-2758",
          "@id": "CVE-2023-2758",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-2758",
          "@id": "CVE-2023-2758",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28399",
          "@id": "CVE-2023-28399",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28651",
          "@id": "CVE-2023-28651",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28657",
          "@id": "CVE-2023-28657",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28713",
          "@id": "CVE-2023-28713",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28824",
          "@id": "CVE-2023-28824",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-29154",
          "@id": "CVE-2023-29154",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/256.html",
          "@id": "CWE-256",
          "@title": "Unprotected Storage of Credentials(CWE-256)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/284.html",
          "@id": "CWE-284",
          "@title": "Improper Access Control(CWE-284)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/732.html",
          "@id": "CWE-732",
          "@title": "Incorrect Permission Assignment for Critical Resource(CWE-732)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/799.html",
          "@id": "CWE-799",
          "@title": "Improper Control of Interaction Frequency(CWE-799)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-89",
          "@title": "SQL Injection(CWE-89)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/918.html",
          "@id": "CWE-918",
          "@title": "Server-Side Request Forgery (SSRF)(CWE-918)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
    }

    JVNDB-2023-001774

    Vulnerability from jvndb - Published: 2023-05-09 07:09 - Updated:2024-06-27 04:30
    Severity
    Summary
    Multiple vulnerabilities in SolarView Compact
    Details
    SolarView Compact provided by CONTEC CO.,LTD. contains multiple vulnerabilities listed below. * Use of hard-coded credentials (CWE-798) - CVE-2023-27512 * OS command injection in the download page (CWE-78) - CVE-2023-27514 * Buffer overflow in the multiple setting pages (CWE-120) - CVE-2023-27518 * OS command injection in the mail setting page (CWE-78) - CVE-2023-27521 * Improper access control in the system date/time setting page (CWE-284) - CVE-2023-27920 CVE-2023-27512, CVE-2023-27514, CVE-2023-27518, CVE-2023-27521 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer. CVE-2023-27920 CONTEC CO.,LTD. reported this vulnerability to JPCERT/CC to notify users of its solutions through JVN.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001774.html",
      "dc:date": "2024-06-27T13:30+09:00",
      "dcterms:issued": "2023-05-09T16:09+09:00",
      "dcterms:modified": "2024-06-27T13:30+09:00",
      "description": "SolarView Compact provided by CONTEC CO.,LTD. contains multiple vulnerabilities listed below.\r\n\r\n  * Use of hard-coded credentials (CWE-798) - CVE-2023-27512\r\n  * OS command injection in the download page (CWE-78) - CVE-2023-27514\r\n  * Buffer overflow in the multiple setting pages (CWE-120) - CVE-2023-27518\r\n  * OS command injection in the mail setting page (CWE-78) - CVE-2023-27521\r\n  * Improper access control in the system date/time setting page (CWE-284) - CVE-2023-27920\r\n\r\nCVE-2023-27512, CVE-2023-27514, CVE-2023-27518, CVE-2023-27521\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.\r\n\r\nCVE-2023-27920\r\nCONTEC CO.,LTD. reported this vulnerability to JPCERT/CC to notify users of its solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001774.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
          "@product": "SolarView Compact SV-CPT-MC310F",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
          "@product": "SolarView Compact SV-CPT-MC310",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2023-001774",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU92106300/index.html",
          "@id": "JVNVU#92106300",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27512",
          "@id": "CVE-2023-27512",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27514",
          "@id": "CVE-2023-27514",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27518",
          "@id": "CVE-2023-27518",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27521",
          "@id": "CVE-2023-27521",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27920",
          "@id": "CVE-2023-27920",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27512",
          "@id": "CVE-2023-27512",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27514",
          "@id": "CVE-2023-27514",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27518",
          "@id": "CVE-2023-27518",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27521",
          "@id": "CVE-2023-27521",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27920",
          "@id": "CVE-2023-27920",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/120.html",
          "@id": "CWE-120",
          "@title": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)(CWE-120)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/284.html",
          "@id": "CWE-284",
          "@title": "Improper Access Control(CWE-284)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/798.html",
          "@id": "CWE-798",
          "@title": "Use of Hard-coded Credentials(CWE-798)"
        }
      ],
      "title": "Multiple vulnerabilities in SolarView Compact"
    }

    JVNDB-2023-001400

    Vulnerability from jvndb - Published: 2023-04-03 07:19 - Updated:2023-04-03 07:19
    Severity
    Summary
    CONPROSYS HMI System(CHS) vulnerable to SQL injection
    Details
    CONPROSYS HMI System(CHS) provided by Contec Co., Ltd. contains an SQL injection vulnerability (CWE-89, CVE-2023-1658). Tenable Network Security reported this vulnerability to the developer. JPCERT/CC coordinated with the reporter and the developer.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001400.html",
      "dc:date": "2023-04-03T16:19+09:00",
      "dcterms:issued": "2023-04-03T16:19+09:00",
      "dcterms:modified": "2023-04-03T16:19+09:00",
      "description": "CONPROSYS HMI System(CHS) provided by Contec Co., Ltd. contains an SQL injection vulnerability (CWE-89, CVE-2023-1658).\r\n\r\nTenable Network Security reported this vulnerability to the developer.\r\nJPCERT/CC coordinated with the reporter and the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001400.html",
      "sec:cpe": {
        "#text": "cpe:/a:contec:conprosys_hmi_system",
        "@product": "CONPROSYS HMI System (CHS)",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "7.5",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2023-001400",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU92145493/index.html",
          "@id": "JVNVU#92145493",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-1658",
          "@id": "CVE-2023-1658",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-89",
          "@title": "SQL Injection(CWE-89)"
        }
      ],
      "title": "CONPROSYS HMI System(CHS) vulnerable to SQL injection"
    }

    JVNDB-2023-001320

    Vulnerability from jvndb - Published: 2023-03-22 04:41 - Updated:2024-06-04 08:00
    Severity
    Summary
    Multiple vulnerabilities in Contec CONPROSYS IoT Gateway products
    Details
    CONPROSYS IoT Gateway products provided by Contec CO.,LTD. contain multiple vulnerabilities listed below. * OS Command Injection (CWE-78) - CVE-2023-27917 Network Maintenance page validates input values improperly, resulting in OS command injection. * Inadequate Encryption Strength (CWE-326) - CVE-2023-27389 Firmware update file contains a firmware image encrypted, which can be decrypted by examining the bundled install script and a little more work. * Improper Access Control (CWE-284) - CVE-2023-23575 Network Maintenance page should be available only to administrative users, but the device fails to restrict access.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001320.html",
      "dc:date": "2024-06-04T17:00+09:00",
      "dcterms:issued": "2023-03-22T13:41+09:00",
      "dcterms:modified": "2024-06-04T17:00+09:00",
      "description": "CONPROSYS IoT Gateway products provided by Contec CO.,LTD. contain multiple vulnerabilities listed below.\r\n\r\n* OS Command Injection (CWE-78) - CVE-2023-27917\r\nNetwork Maintenance page validates input values improperly, resulting in OS command injection.\r\n* Inadequate Encryption Strength (CWE-326) - CVE-2023-27389\r\nFirmware update file contains a firmware image encrypted, which can be decrypted by examining the bundled install script and a little more work.\r\n* Improper Access Control (CWE-284) - CVE-2023-23575\r\nNetwork Maintenance page should be available only to administrative users, but the device fails to restrict access.",
      "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001320.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:cps-mc341-a1-111_firmware",
          "@product": "CPS-MC341-A1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-adsc1-111_firmware",
          "@product": "CPS-MC341-ADSC1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-adsc1-931_firmware",
          "@product": "CPS-MC341-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-adsc2-111_firmware",
          "@product": "CPS-MC341-ADSC2-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-ds1-111_firmware",
          "@product": "CPS-MC341-DS1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-ds11-111_firmware",
          "@product": "CPS-MC341-DS11-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341-ds2-911_firmware",
          "@product": "CPS-MC341-DS2-911",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341g-adsc1-110_firmwar",
          "@product": "CPS-MC341G-ADSC1-110",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mc341q-adsc1-111_firmware",
          "@product": "CPS-MC341Q-ADSC1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mcs341-ds1-111_firmware",
          "@product": "CPS-MCS341-DS1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mcs341-ds1-131_firmware",
          "@product": "CPS-MCS341-DS1-131",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mcs341g-ds1-130_firmware",
          "@product": "CPS-MCS341G-DS1-130",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mcs341g5-ds1-130_firmware",
          "@product": "CPS-MCS341G5-DS1-130",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mcs341q-ds1-131_firmware",
          "@product": "CPS-MCS341Q-DS1-131",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mg341-adsc1-111_firmware",
          "@product": "CPS-MG341-ADSC1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mg341-adsc1-931_firmware",
          "@product": "CPS-MG341-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mg341g-adsc1-111_firmware",
          "@product": "CPS-MG341G-ADSC1-111",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mg341g-adsc1-930_firmware",
          "@product": "CPS-MG341G-ADSC1-930",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:cps-mg341g5-adsc1-931_firmware",
          "@product": "CPS-MG341G5-ADSC1-931",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2023-001320",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/vu/JVNVU96198617/index.html",
          "@id": "JVNVU#96198617",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27917",
          "@id": "CVE-2023-27917",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-27389",
          "@id": "CVE-2023-27389",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-23575",
          "@id": "CVE-2023-23575",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-23575",
          "@id": "CVE-2023-23575",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27389",
          "@id": "CVE-2023-27389",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27917",
          "@id": "CVE-2023-27917",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/284.html",
          "@id": "CWE-284",
          "@title": "Improper Access Control(CWE-284)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/326.html",
          "@id": "CWE-326",
          "@title": "Inadequate Encryption Strength(CWE-326)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec CONPROSYS IoT Gateway products"
    }

    JVNDB-2023-001108

    Vulnerability from jvndb - Published: 2023-01-24 04:38 - Updated:2023-01-24 04:38
    Severity
    Summary
    Contec CONPROSYS HMI System (CHS) vulnerable to multiple SQL injections
    Details
    CONPROSYS HMI System (CHS) provided by CONTEC CO.,LTD. contains multiple SQL injection vulnerabilities (CWE-89). Mosin from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc., reported these vulnerabilities to Contec Co., Ltd. Contec Co., Ltd. reported the issues to JPCERT/CC in order to notify the solutions to the users through JVN.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001108.html",
      "dc:date": "2023-01-24T13:38+09:00",
      "dcterms:issued": "2023-01-24T13:38+09:00",
      "dcterms:modified": "2023-01-24T13:38+09:00",
      "description": "CONPROSYS HMI System (CHS) provided by CONTEC CO.,LTD. contains multiple SQL injection vulnerabilities (CWE-89).\r\n\r\nMosin from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc., reported these vulnerabilities to Contec Co., Ltd.\r\nContec Co., Ltd. reported the issues to JPCERT/CC in order to notify the solutions to the users through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001108.html",
      "sec:cpe": {
        "#text": "cpe:/a:contec:conprosys_hmi_system",
        "@product": "CONPROSYS HMI System (CHS)",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "4.3",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2023-001108",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU97195023/index.html",
          "@id": "JVNVU#97195023",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-22324",
          "@id": "CVE-2023-22324",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22324",
          "@id": "CVE-2023-22324",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-89",
          "@title": "SQL Injection(CWE-89)"
        }
      ],
      "title": "Contec CONPROSYS HMI System (CHS) vulnerable to multiple SQL injections"
    }

    JVNDB-2022-002779

    Vulnerability from jvndb - Published: 2022-12-16 04:29 - Updated:2023-01-11 07:55
    Severity
    Summary
    Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
    Details
    CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below. * OS Command Injection (CWE-78) - CVE-2022-44456 * Use of Default Credentials (CWE-1392) - CVE-2023-22331 * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334 * Cross-site Scripting (CWE-79) - CVE-2023-22373 * Improper Access Control (CWE-284) - CVE-2023-22339 Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002779.html",
      "dc:date": "2023-01-11T16:55+09:00",
      "dcterms:issued": "2022-12-16T13:29+09:00",
      "dcterms:modified": "2023-01-11T16:55+09:00",
      "description": "CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n \r\n  * OS Command Injection (CWE-78) - CVE-2022-44456\r\n  * Use of Default Credentials (CWE-1392) - CVE-2023-22331\r\n  * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334\r\n  * Cross-site Scripting (CWE-79) - CVE-2023-22373\r\n  * Improper Access Control (CWE-284) - CVE-2023-22339\r\n\r\nFloris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002779.html",
      "sec:cpe": {
        "#text": "cpe:/a:contec:conprosys_hmi_system",
        "@product": "CONPROSYS HMI System (CHS)",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "10.0",
        "@severity": "Critical",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2022-002779",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU96873821/index.html",
          "@id": "JVNVU#96873821",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-44456",
          "@id": "CVE-2022-44456",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-22331",
          "@id": "CVE-2023-22331",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-22334",
          "@id": "CVE-2023-22334",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-22373",
          "@id": "CVE-2023-22373",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-22339",
          "@id": "CVE-2023-22339",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-44456",
          "@id": "CVE-2022-44456",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22331",
          "@id": "CVE-2023-22331",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22334",
          "@id": "CVE-2023-22334",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22339",
          "@id": "CVE-2023-22339",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22373",
          "@id": "CVE-2023-22373",
          "@source": "NVD"
        },
        {
          "#text": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-347-03",
          "@id": "ICSA-22-347-03",
          "@source": "ICS-CERT ADVISORY"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/836.html",
          "@id": "CWE-836",
          "@title": "Use of Password Hash Instead of Password for Authentication(CWE-836)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/284.html",
          "@id": "CWE-284",
          "@title": "Improper Access Control(CWE-284)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/1392.html",
          "@id": "CWE-1392",
          "@title": "Use of Default Credentials(CWE-1392)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
    }

    JVNDB-2022-002770

    Vulnerability from jvndb - Published: 2022-12-06 06:08 - Updated:2024-06-04 08:13
    Severity
    Summary
    Contec SolarView Compact vulnerable to cross-site scripting
    Details
    SolarView Compact provided by Contec Co., Ltd. is PV Measurement System. SolarView Compact contains a cross-site scripting vulnerability (CWE-79, CVE-2022-44355) in Check Network Communication Page of the product's web server. As of 2022 December 5, a Proof-of-Concept (PoC) code exploiting this vulnerability has already been made public.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002770.html",
      "dc:date": "2024-06-04T17:13+09:00",
      "dcterms:issued": "2022-12-06T15:08+09:00",
      "dcterms:modified": "2024-06-04T17:13+09:00",
      "description": "SolarView Compact provided by Contec Co., Ltd. is PV Measurement System.\r\nSolarView Compact contains a cross-site scripting vulnerability (CWE-79, CVE-2022-44355) in Check Network Communication Page of the product\u0027s web server.\r\n\r\nAs of 2022 December 5, a Proof-of-Concept (PoC) code exploiting this vulnerability has already been made public.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002770.html",
      "sec:cpe": {
        "#text": "cpe:/o:contec:solarview_compact_firmware",
        "@product": "SolarView Compact firmware",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "5.4",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2022-002770",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/vu/JVNVU93526386/index.html",
          "@id": "JVNVU#93526386",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-44355",
          "@id": "CVE-2022-44355",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-44355",
          "@id": "CVE-2022-44355",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "Contec SolarView Compact vulnerable to cross-site scripting"
    }

    JVNDB-2022-002346

    Vulnerability from jvndb - Published: 2022-09-02 09:08 - Updated:2022-09-02 09:08
    Severity
    Summary
    Multiple vulnerabilities in Contec FLEXLAN FX3000 and FX2000 series
    Details
    FLEXLAN FX3000 and FX2000 series provided by Contec Co., Ltd. contain multiple vulnerabilities listed below. * Hidden Functionality (CWE-912) - CVE-2022-36158 * Use of Hard-coded Credentials (CWE-798) - CVE-2022-36159 Thomas J. Knudsen and Samy Younsi of Necrum Security Labs reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002346.html",
      "dc:date": "2022-09-02T18:08+09:00",
      "dcterms:issued": "2022-09-02T18:08+09:00",
      "dcterms:modified": "2022-09-02T18:08+09:00",
      "description": "FLEXLAN FX3000 and FX2000 series provided by Contec Co., Ltd. contain multiple vulnerabilities listed below.\r\n  * Hidden Functionality (CWE-912) - CVE-2022-36158\r\n  * Use of Hard-coded Credentials (CWE-798) - CVE-2022-36159\r\n\r\nThomas J. Knudsen and Samy Younsi of Necrum Security Labs reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002346.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:flexlan_fx2000_firmware",
          "@product": "FLEXLAN FX2000 firmware",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:flexlan_fx3000_firmware",
          "@product": "FLEXLAN FX3000 firmware",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.0",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2022-002346",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/vu/JVNVU98305100/index.html",
          "@id": "JVNVU#98305100",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-36158",
          "@id": "CVE-2022-36158",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-36159",
          "@id": "CVE-2022-36159",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-36158",
          "@id": "CVE-2022-36158",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-36159",
          "@id": "CVE-2022-36159",
          "@source": "NVD"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/798.html",
          "@id": "CWE-798",
          "@title": "Use of Hard-coded Credentials(CWE-798)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/912.html",
          "@id": "CWE-912",
          "@title": "Hidden Functionality(CWE-912)"
        }
      ],
      "title": "Multiple vulnerabilities in Contec FLEXLAN FX3000 and FX2000 series"
    }

    JVNDB-2022-002112

    Vulnerability from jvndb - Published: 2022-08-03 08:40 - Updated:2024-06-14 06:21
    Severity
    Summary
    CONTEC SolarView Compact vulnerable to insufficient verification in uploading files
    Details
    SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System. The image file management page of SolarView Compact contains an insufficient verification vulnerability when uploadi webray reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.ng files (CWE-20).
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002112.html",
      "dc:date": "2024-06-14T15:21+09:00",
      "dcterms:issued": "2022-08-03T17:40+09:00",
      "dcterms:modified": "2024-06-14T15:21+09:00",
      "description": "SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System.\r\nThe image file management page of SolarView Compact contains an insufficient verification vulnerability when uploadi\r\n\r\nwebray reported this vulnerability to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.ng files (CWE-20).",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002112.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
          "@product": "SolarView Compact SV-CPT-MC310F",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
          "@product": "SolarView Compact SV-CPT-MC310",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2022-002112",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU93696585/",
          "@id": "JVNVU#93696585",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-35239",
          "@id": "CVE-2022-35239",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-35239",
          "@id": "CVE-2022-35239",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-20",
          "@title": "Improper Input Validation(CWE-20)"
        }
      ],
      "title": "CONTEC SolarView Compact vulnerable to insufficient verification in uploading files"
    }

    JVNDB-2022-001923

    Vulnerability from jvndb - Published: 2022-05-27 06:28 - Updated:2024-06-20 02:34
    Severity
    Summary
    Multiple vulnerabilities in CONTEC SolarView Compact
    Details
    SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System. SolarView Compact contains multiple vulnerabilities listed below. OS command injection (CWE-78) - CVE-2022-29303 Improper validation of input values on the send test mail console of the product's web server may result in OS command injection. Directory traversal (CWE-23) - CVE-2022-29298 Improper validation of a URL on the download page of the product's web server may allow a remote attacker to view and obtain an arbitrary file. Information disclosure (CWE-200) - CVE-2022-29302 The hidden page which enables to edit the product's web server contents exists in the product's web server, and a remote attacker to read and/or alter an arbitrary file on the web server via the hidden page. OS command injection (CWE-78) - CVE-2022-40881 Improper validation of input values on Check Network Communication Page of the product's web server may result in an arbitrary OS command execution. OS command injection (CWE-78) - CVE-2023-23333 Improper validation of input values on the download page of the product's web server may result in an arbitrary OS command execution. CVE-2022-29298 Jongheon Yan of S2W Inc reported CONTEC CO., LTD. that the fix for the vulnerability was insufficient in Ver.6.5. CONTEC CO., LTD. and JPCERT/CC updated respective advisories.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-001923.html",
      "dc:date": "2024-06-20T11:34+09:00",
      "dcterms:issued": "2022-05-27T15:28+09:00",
      "dcterms:modified": "2024-06-20T11:34+09:00",
      "description": "SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System. SolarView Compact contains multiple vulnerabilities listed below.\r\n\r\nOS command injection (CWE-78) - CVE-2022-29303\r\nImproper validation of input values on the send test mail console of the product\u0027s web server may result in OS command injection.\r\n\r\nDirectory traversal (CWE-23) - CVE-2022-29298\r\nImproper validation of a URL on the download page of the product\u0027s web server may allow a remote attacker to view and obtain an arbitrary file.\r\n\r\nInformation disclosure (CWE-200) - CVE-2022-29302\r\nThe hidden page which enables to edit the product\u0027s web server contents exists in the product\u0027s web server, and a remote attacker to read and/or alter an arbitrary file on the web server via the hidden page.\r\n\r\nOS command injection (CWE-78) - CVE-2022-40881\r\nImproper validation of input values on Check Network Communication Page of the product\u0027s web server may result in an arbitrary OS command execution.\r\n\r\nOS command injection (CWE-78) - CVE-2023-23333\r\nImproper validation of input values on the download page of the product\u0027s web server may result in an arbitrary OS command execution.\r\n\r\nCVE-2022-29298\r\nJongheon Yan of S2W Inc reported CONTEC CO., LTD. that the fix for the vulnerability was insufficient in Ver.6.5. CONTEC CO., LTD. and JPCERT/CC updated respective advisories.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-001923.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
          "@product": "SolarView Compact SV-CPT-MC310F",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
          "@product": "SolarView Compact SV-CPT-MC310F",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
          "@product": "SolarView Compact SV-CPT-MC310",
          "@vendor": "Contec",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
          "@product": "SolarView Compact SV-CPT-MC310",
          "@vendor": "Contec",
          "@version": "2.2"
        }
      ],
      "sec:cvss": [
        {
          "@score": "5.0",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "@version": "2.0"
        },
        {
          "@score": "9.8",
          "@severity": "Critical",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2022-001923",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/vu/JVNVU92327282/index.html",
          "@id": "JVNVU#92327282",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-29303",
          "@id": "CVE-2022-29303",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-29298",
          "@id": "CVE-2022-29298",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-29302",
          "@id": "CVE-2022-29302",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-40881",
          "@id": "CVE-2022-40881",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2023-23333",
          "@id": "CVE-2023-23333",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29303",
          "@id": "CVE-2022-29303",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29298",
          "@id": "CVE-2022-29298",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29302",
          "@id": "CVE-2022-29302",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-40881",
          "@id": "CVE-2022-40881",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-23333",
          "@id": "CVE-2023-23333",
          "@source": "NVD"
        },
        {
          "#text": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "@id": "CVE-2022-29303",
          "@source": "CISA Known Exploited Vulnerabilities Catalog"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/23.html",
          "@id": "CWE-23",
          "@title": "Relative Path Traversal(CWE-23)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-200",
          "@title": "Information Exposure(CWE-200)"
        }
      ],
      "title": "Multiple vulnerabilities in CONTEC SolarView Compact"
    }

    JVNDB-2021-000016

    Vulnerability from jvndb - Published: 2021-02-19 07:44 - Updated:2021-02-25 06:31
    Severity
    Summary
    Multiple vulnerabilities in SolarView Compact
    Details
    SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below. *Exposure of information through directory listing (CWE-548) - CVE-2021-20656 *Improper access control (CWE-284) - CVE-2021-20657 *OS command injection (CWE-78) - CVE-2021-20658 *Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659 *Cross-site scripting (CWE-79) - CVE-2021-20660 *Directory traversal (CWE-23) - CVE-2021-20661 *Missing authentication for critical function (CWE-306) - CVE-2021-20662 *Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324 The product uses previous versions of vsfpd and lighttpd with known vulnerabilities. CVE-2021-20656 Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2021-20657, CVE-2021-20658 Takayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662 Kouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported to IPA that CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323 and CVE-2014-2324 vulnerabilities still exist in the product. JPCERT/CC coordinated with the developer.
    References
    JVN https://jvn.jp/en/jp/JVN37417423/index.html
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0762
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4362
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4508
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4559
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4560
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2323
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2324
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20656
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20657
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20658
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20659
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20660
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20661
    CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20662
    NVD https://nvd.nist.gov/vuln/detail/CVE-2011-0762
    NVD https://nvd.nist.gov/vuln/detail/CVE-2011-4362
    NVD https://nvd.nist.gov/vuln/detail/CVE-2013-4508
    NVD https://nvd.nist.gov/vuln/detail/CVE-2013-4559
    NVD https://nvd.nist.gov/vuln/detail/CVE-2013-4560
    NVD https://nvd.nist.gov/vuln/detail/CVE-2014-2323
    NVD https://nvd.nist.gov/vuln/detail/CVE-2014-2324
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20656
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20657
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20658
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20659
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20660
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20661
    NVD https://nvd.nist.gov/vuln/detail/CVE-2021-20662
    Information Exposure(CWE-200) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Path Traversal(CWE-22) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Permissions(CWE-264) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    OS Command Injection(CWE-78) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Cross-site Scripting(CWE-79) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    No Mapping(CWE-Other) https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000016.html",
      "dc:date": "2021-02-25T15:31+09:00",
      "dcterms:issued": "2021-02-19T16:44+09:00",
      "dcterms:modified": "2021-02-25T15:31+09:00",
      "description": "SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n\r\n*Exposure of information through directory listing (CWE-548) - CVE-2021-20656\r\n*Improper access control (CWE-284) - CVE-2021-20657\r\n*OS command injection (CWE-78) - CVE-2021-20658\r\n*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659\r\n*Cross-site scripting (CWE-79) - CVE-2021-20660\r\n*Directory traversal (CWE-23) - CVE-2021-20661\r\n*Missing authentication for critical function (CWE-306) - CVE-2021-20662\r\n*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324\r\nThe product uses previous versions of vsfpd and lighttpd with known vulnerabilities.\r\n\r\nCVE-2021-20656\r\nKouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nCVE-2021-20657, CVE-2021-20658\r\nTakayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nCVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662\r\nKouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nKouichirou Okada, Katsunari Yoshioka of Yokohama National University reported to IPA that CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323 and CVE-2014-2324 vulnerabilities still exist in the product. JPCERT/CC coordinated with the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000016.html",
      "sec:cpe": {
        "#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
        "@product": "SolarView Compact SV-CPT-MC310",
        "@vendor": "Contec",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.8",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "6.3",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2021-000016",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN37417423/index.html",
          "@id": "JVN#37417423",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0762",
          "@id": "CVE-2011-0762",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4362",
          "@id": "CVE-2011-4362",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4508",
          "@id": "CVE-2013-4508",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4559",
          "@id": "CVE-2013-4559",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4560",
          "@id": "CVE-2013-4560",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2323",
          "@id": "CVE-2014-2323",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2324",
          "@id": "CVE-2014-2324",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20656",
          "@id": "CVE-2021-20656",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20657",
          "@id": "CVE-2021-20657",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20658",
          "@id": "CVE-2021-20658",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20659",
          "@id": "CVE-2021-20659",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20660",
          "@id": "CVE-2021-20660",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20661",
          "@id": "CVE-2021-20661",
          "@source": "CVE"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20662",
          "@id": "CVE-2021-20662",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2011-0762",
          "@id": "CVE-2011-0762",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2011-4362",
          "@id": "CVE-2011-4362",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4508",
          "@id": "CVE-2013-4508",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4559",
          "@id": "CVE-2013-4559",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4560",
          "@id": "CVE-2013-4560",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2014-2323",
          "@id": "CVE-2014-2323",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2014-2324",
          "@id": "CVE-2014-2324",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20656",
          "@id": "CVE-2021-20656",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20657",
          "@id": "CVE-2021-20657",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20658",
          "@id": "CVE-2021-20658",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20659",
          "@id": "CVE-2021-20659",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20660",
          "@id": "CVE-2021-20660",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20661",
          "@id": "CVE-2021-20661",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20662",
          "@id": "CVE-2021-20662",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-200",
          "@title": "Information Exposure(CWE-200)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-22",
          "@title": "Path Traversal(CWE-22)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-264",
          "@title": "Permissions(CWE-264)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in SolarView Compact"
    }

    CVE-2026-82789 (GCVE-0-2026-82789)

    Vulnerability from cvelistv5 – Published: 2026-09-14 06:44 – Updated: 2026-09-14 15:45
    VLAI
    Summary
    An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 15:38 UTC
    CWE
    • CWE-95 - Improper neutralization of directives in dynamically evaluated code ('Eval Injection')
    Impacted products
    Vendor Product Version
    Contec CONPROSYS HMI System(CHS) Affected: 0 , < 3.8.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82789",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T15:38:44.904489Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T15:45:31.910Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CONPROSYS HMI System(CHS)",
              "vendor": "Contec",
              "versions": [
                {
                  "lessThan": "3.8.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An improper neutralization of directives in dynamically evaluated code (\u0027Eval Injection\u0027) issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en-US",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en-US",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-95",
                  "description": "Improper neutralization of directives in dynamically evaluated code (\u0027Eval Injection\u0027)",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T06:44:56.367Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU96551518/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2026-82789",
        "datePublished": "2026-09-14T06:44:56.367Z",
        "dateReserved": "2026-08-31T02:30:58.279Z",
        "dateUpdated": "2026-09-14T15:45:31.910Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-46509 (GCVE-0-2023-46509)

    Vulnerability from cvelistv5 – Published: 2023-10-27 00:00 – Updated: 2024-09-12 14:13
    VLAI
    Summary
    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 14:15 UTC
    CWE
    • n/a
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    contec solarview_compact Affected: 0 , ≤ 6.0 (custom)
        cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T20:45:42.270Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "solarview_compact",
                "vendor": "contec",
                "versions": [
                  {
                    "lessThanOrEqual": "6.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-46509",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T14:15:34.861950Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-12T14:13:31.239Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-27T20:40:22.919Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-46509",
        "datePublished": "2023-10-27T00:00:00.000Z",
        "dateReserved": "2023-10-23T00:00:00.000Z",
        "dateUpdated": "2024-09-12T14:13:31.239Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-2758 (GCVE-0-2023-2758)

    Vulnerability from cvelistv5 – Published: 2023-05-31 14:09 – Updated: 2025-01-09 20:26
    VLAI
    Title
    Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service
    Summary
    A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-09 20:25 UTC
    CWE
    Impacted products
    Vendor Product Version
    Contec CONPROSYS HMI System Affected: 0 , ≤ 3.5.2 (custom)
    Create a notification for this product.
    Date Public
    2023-05-31 14:08
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T06:33:05.476Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.tenable.com/security/research/tra-2023-21"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/vu/JVNVU93372935/index.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-2758",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-09T20:25:29.496343Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-09T20:26:25.295Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CONPROSYS HMI System",
              "vendor": "Contec",
              "versions": [
                {
                  "lessThanOrEqual": "3.5.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2023-05-31T14:08:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time."
                }
              ],
              "value": "A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-799",
                  "description": "CWE-799",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-31T14:09:49.809Z",
            "orgId": "5ac1ecc2-367a-4d16-a0b2-35d495ddd0be",
            "shortName": "tenable"
          },
          "references": [
            {
              "url": "https://www.tenable.com/security/research/tra-2023-21"
            },
            {
              "url": "https://jvn.jp/en/vu/JVNVU93372935/index.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "5ac1ecc2-367a-4d16-a0b2-35d495ddd0be",
        "assignerShortName": "tenable",
        "cveId": "CVE-2023-2758",
        "datePublished": "2023-05-31T14:09:49.809Z",
        "dateReserved": "2023-05-17T12:46:36.673Z",
        "dateUpdated": "2025-01-09T20:26:25.295Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }