Search
Find a vulnerability
Search criteria
19 vulnerabilities by Contec
JVNDB-2026-032931
Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-14 07:32
Severity
Summary
Multiple vulnerabilities in Contec PC-HELPER series
Details
PC-HELPER series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
- Cross-site scripting (CWE-79) - CVE-2026-82790
- Cross-site request forgery (CWE-352) - CVE-2026-82764
- OS command injection (CWE-78) - CVE-2026-82791
- Cross-site scripting (CWE-79) - CVE-2026-82792
- Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82793
References
| Type | URL | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032931.html",
"dc:date": "2026-09-14T16:32+09:00",
"dcterms:issued": "2026-09-14T16:32+09:00",
"dcterms:modified": "2026-09-14T16:32+09:00",
"description": "PC-HELPER series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/434.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82790\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82791\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82792\u003c/li\u003e\u003cli\u003eUnrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82793\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032931.html",
"sec:cpe": [
{
"#text": "cpe:/h:contec:can-2-usb",
"@product": "CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-USB",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:can-2-wf",
"@product": "CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-WF",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:dio-0404ry-lwf",
"@product": "PC-HELPER Wireless I/O DIO-0404RY-LWF",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:dio-0404ry-lwf-us",
"@product": "PC-HELPER Wireless I/O DIO-0404RY-LWF-US",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "5.4",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-032931",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU90314828/index.html",
"@id": "JVNVU#90314828",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
"@id": "CVE-2026-82764",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82790",
"@id": "CVE-2026-82790",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82791",
"@id": "CVE-2026-82791",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82792",
"@id": "CVE-2026-82792",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82793",
"@id": "CVE-2026-82793",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-352",
"@title": "Cross-Site Request Forgery(CWE-352)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/434.html",
"@id": "CWE-434",
"@title": "Unrestricted Upload of File with Dangerous Type(CWE-434)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Multiple vulnerabilities in Contec PC-HELPER series"
}
JVNDB-2026-033234
Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-15 03:40
Severity
Summary
Multiple vulnerabilities in Contec FLEXLAN series
Details
FLEXLAN series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
- OS command injection (CWE-78) - CVE-2026-82762, CVE-2026-82766
- Cross-site scripting (CWE-79) - CVE-2026-82763, CVE-2026-82769, CVE-2026-82771
- Cross-site request forgery (CWE-352) - CVE-2026-82764
- Path traversal (CWE-23) - CVE-2026-82765, CVE-2026-82768
- Cross-site scripting (CWE-79) - CVE-2026-82767
- Buffer overflow (CWE-120) - CVE-2026-82770, CVE-2026-82772
References
Impacted products
| Vendor | Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033234.html",
"dc:date": "2026-09-15T12:40+09:00",
"dcterms:issued": "2026-09-14T16:32+09:00",
"dcterms:modified": "2026-09-15T12:40+09:00",
"description": "FLEXLAN series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/23.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/120.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82762, CVE-2026-82766\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82763, CVE-2026-82769, CVE-2026-82771\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003ePath traversal (CWE-23) - CVE-2026-82765, CVE-2026-82768\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82767\u003c/li\u003e\u003cli\u003eBuffer overflow (CWE-120) - CVE-2026-82770, CVE-2026-82772\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033234.html",
"sec:cpe": [
{
"#text": "cpe:/h:contec:ece1000",
"@product": "ECE1000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:ece1020",
"@product": "ECE1020",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:ecs1020",
"@product": "ECS1020",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa3000",
"@product": "FXA3000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa3000-",
"@product": "FXA3000-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa3020",
"@product": "FXA3020",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa3020-",
"@product": "FXA3020-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa3200",
"@product": "FXA3200",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa5000",
"@product": "FXA5000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa5020",
"@product": "FXA5020",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxa5020-",
"@product": "FXA5020-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe3000",
"@product": "FXE3000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe3000-",
"@product": "FXE3000-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe3000-wp",
"@product": "FXE3000-WP",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe4000",
"@product": "FXE4000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe4000-wp",
"@product": "FXE4000-WP",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe5000",
"@product": "FXE5000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxe5000-",
"@product": "FXE5000-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxs300_-cn",
"@product": "FXS300[]-CN",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxs4000",
"@product": "FXS4000",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxs4020",
"@product": "FXS4020",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxs5000-",
"@product": "FXS5000-[][]",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:fxs5021",
"@product": "FXS5021",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:rp-wah-sr1",
"@product": "RP-WAH-SR1",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:rp-wah-sr12",
"@product": "RP-WAH-SR12",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:rp-wah-sr2",
"@product": "RP-WAH-SR2",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:rp-wah-sr22",
"@product": "RP-WAH-SR22",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:sga1000",
"@product": "SGA1000",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-033234",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU99009004/index.html",
"@id": "JVNVU#99009004",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82762",
"@id": "CVE-2026-82762",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82763",
"@id": "CVE-2026-82763",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
"@id": "CVE-2026-82764",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82765",
"@id": "CVE-2026-82765",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82766",
"@id": "CVE-2026-82766",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82767",
"@id": "CVE-2026-82767",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82768",
"@id": "CVE-2026-82768",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82769",
"@id": "CVE-2026-82769",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82770",
"@id": "CVE-2026-82770",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82771",
"@id": "CVE-2026-82771",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82772",
"@id": "CVE-2026-82772",
"@source": "CVE"
},
{
"#text": "https://cwe.mitre.org/data/definitions/120.html",
"@id": "CWE-120",
"@title": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)(CWE-120)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/23.html",
"@id": "CWE-23",
"@title": "Relative Path Traversal(CWE-23)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-352",
"@title": "Cross-Site Request Forgery(CWE-352)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Multiple vulnerabilities in Contec FLEXLAN series"
}
JVNDB-2026-032930
Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-14 07:32
Severity
Summary
Multiple vulnerabilities in SolarView Compact
Details
SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
- OS command injection in Schedule Settings (CWE-78) - CVE-2026-82794
- Cross-site scripting in Schedule Settings and Mail Send Setting (CWE-79) - CVE-2026-82795
- Cross-site scripting in Image Management (CWE-79) - CVE-2026-82796
References
| Type | URL | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032930.html",
"dc:date": "2026-09-14T16:32+09:00",
"dcterms:issued": "2026-09-14T16:32+09:00",
"dcterms:modified": "2026-09-14T16:32+09:00",
"description": "SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOS command injection in Schedule Settings (CWE-78) - CVE-2026-82794\u003c/li\u003e\u003cli\u003eCross-site scripting in Schedule Settings and Mail Send Setting (CWE-79) - CVE-2026-82795\u003c/li\u003e\u003cli\u003eCross-site scripting in Image Management (CWE-79) - CVE-2026-82796\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-032930.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
"@product": "SolarView Compact SV-CPT-MC310F",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-032930",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU97753461/index.html",
"@id": "JVNVU#97753461",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82794",
"@id": "CVE-2026-82794",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82795",
"@id": "CVE-2026-82795",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82796",
"@id": "CVE-2026-82796",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Multiple vulnerabilities in SolarView Compact"
}
JVNDB-2026-033235
Vulnerability from jvndb - Published: 2026-09-14 07:32 - Updated:2026-09-29 03:18
Severity
Summary
Multiple vulnerabilities in Contec CONPROSYS series
Details
CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
- Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788
- OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779
- Exposure of information through directory listing (CWE-548) - CVE-2026-82775, CVE-2026-82778
- Dependency on vulnerable third-party component (CWE-1395)
- This issue is caused by a vulnerability in chart.js (CVE-2020-7746).
- Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82780
- Cross-site scripting (CWE-79) - CVE-2026-82781
- Out-of-bounds write (CWE-787) - CVE-2026-82782
- Cross-site request forgery (CWE-352) - CVE-2026-82764
- Plaintext storage of a password (CWE-256) - CVE-2026-82783
- Missing authentication for critical function (CWE-306) - CVE-2026-82784
- Stack-based buffer overflow (CWE-121) - CVE-2026-82785
- Insufficiently protected credentials (CWE-522) - CVE-2026-82786
- Missing authentication for critical function (CWE-306) - CVE-2026-82787
- Eval injection (CWE-95) - CVE-2026-82789
References
| Type | URL | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033235.html",
"dc:date": "2026-09-29T12:18+09:00",
"dcterms:issued": "2026-09-14T16:32+09:00",
"dcterms:modified": "2026-09-29T12:18+09:00",
"description": "CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/548.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/1395.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2020-7746\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/434.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/787.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/352.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/256.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/121.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/522.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/95.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788\u003c/li\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779\u003c/li\u003e\u003cli\u003eExposure of information through directory listing (CWE-548) - CVE-2026-82775, CVE-2026-82778\u003c/li\u003e\u003cli\u003eDependency on vulnerable third-party component (CWE-1395)\u003c/li\u003e\u003cul\u003e\u003cli\u003eThis issue is caused by a vulnerability in chart.js (CVE-2020-7746).\u003c/li\u003e\u003c/ul\u003e\u003cli\u003eUnrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82780\u003c/li\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-82781\u003c/li\u003e\u003cli\u003eOut-of-bounds write (CWE-787) - CVE-2026-82782\u003c/li\u003e\u003cli\u003eCross-site request forgery (CWE-352) - CVE-2026-82764\u003c/li\u003e\u003cli\u003ePlaintext storage of a password (CWE-256) - CVE-2026-82783\u003c/li\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-82784\u003c/li\u003e\u003cli\u003eStack-based buffer overflow (CWE-121) - CVE-2026-82785\u003c/li\u003e\u003cli\u003eInsufficiently protected credentials (CWE-522) - CVE-2026-82786\u003c/li\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-82787\u003c/li\u003e\u003cli\u003eEval injection (CWE-95) - CVE-2026-82789\u003c/li\u003e\u003c/ul\u003eContec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-033235.html",
"sec:cpe": [
{
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:configurable_type_cps-pcs341_-ds1-120",
"@product": "Configurable type CPS-PCS341[][]-DS1-1201",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cps-tm341g5mb-adsc1-931",
"@product": "CPS-TM341G5MB-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cps-tm341gmb-adsc1-931",
"@product": "CPS-TM341GMB-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cps-tm341mb-adsc1-931",
"@product": "CPS-TM341MB-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cpsl-08p1en",
"@product": "CPSL-08P1EN",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cpsn-eob471ei-",
"@product": "Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cpsn-mcb271-",
"@product": "Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:cpsn-pcb271-s1-041",
"@product": "Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:integrated_type_cps-pc341_-9201",
"@product": "Integrated Type CPS-PC341[][]-*-9201",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:m2m_controller_configurable_type_cps-mcs341",
"@product": "M2M Controller Configurable type CPS-MCS341*",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:m2m_controller_integrated_type_cps-mc341",
"@product": "M2M Controller Integrated Type CPS-MC341",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:m2m_gateway_configurable_type_cps-mgs341",
"@product": "M2M Gateway Configurable type CPS-MGS341*",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/h:contec:m2m_gateway_integrated_type_cps-mg341",
"@product": "M2M Gateway Integrated Type CPS-MG341*",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "6.1",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-033235",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU96551518/index.html",
"@id": "JVNVU#96551518",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2020-7746",
"@id": "CVE-2020-7746",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82764",
"@id": "CVE-2026-82764",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82773",
"@id": "CVE-2026-82773",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82774",
"@id": "CVE-2026-82774",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82775",
"@id": "CVE-2026-82775",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82776",
"@id": "CVE-2026-82776",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82777",
"@id": "CVE-2026-82777",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82778",
"@id": "CVE-2026-82778",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82779",
"@id": "CVE-2026-82779",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82780",
"@id": "CVE-2026-82780",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82781",
"@id": "CVE-2026-82781",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82782",
"@id": "CVE-2026-82782",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82783",
"@id": "CVE-2026-82783",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82784",
"@id": "CVE-2026-82784",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82785",
"@id": "CVE-2026-82785",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82786",
"@id": "CVE-2026-82786",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82787",
"@id": "CVE-2026-82787",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82788",
"@id": "CVE-2026-82788",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-82789",
"@id": "CVE-2026-82789",
"@source": "CVE"
},
{
"#text": "https://cwe.mitre.org/data/definitions/121.html",
"@id": "CWE-121",
"@title": "Stack-based Buffer Overflow(CWE-121)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/1395.html",
"@id": "CWE-1395",
"@title": "Dependency on Vulnerable Third-Party Component(CWE-1395)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/256.html",
"@id": "CWE-256",
"@title": "Unprotected Storage of Credentials(CWE-256)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/306.html",
"@id": "CWE-306",
"@title": "Missing Authentication for Critical Function(CWE-306)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-352",
"@title": "Cross-Site Request Forgery(CWE-352)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/434.html",
"@id": "CWE-434",
"@title": "Unrestricted Upload of File with Dangerous Type(CWE-434)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/522.html",
"@id": "CWE-522",
"@title": "Insufficiently Protected Credentials(CWE-522)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/548.html",
"@id": "CWE-548",
"@title": "Exposure of Information Through Directory Listing(CWE-548)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/787.html",
"@id": "CWE-787",
"@title": "Out-of-bounds Write(CWE-787)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/95.html",
"@id": "CWE-95",
"@title": "Improper Neutralization of Directives in Dynamically Evaluated Code (\u0027Eval Injection\u0027)(CWE-95)"
}
],
"title": "Multiple vulnerabilities in Contec CONPROSYS series"
}
JVNDB-2025-007754
Vulnerability from jvndb - Published: 2025-07-02 02:31 - Updated:2025-07-02 02:31
Severity
Summary
Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
Details
CONPROSYS HMI System (CHS) provided by Contec Co.,Ltd. contains multiple vulnerabilities listed below.
* Reflected cross-site scripting (CWE-79) - CVE-2025-34080
* Insertion of sensitive information into debugging code (CWE-215) - CVE-2025-34081
Alex Williams of Converge Technology Solutions reported these vulnerabilities to Vulncheck Inc., and
Vulncheck Inc. reported these vulnerabilities to the developer.
Based on the coordination request made by the developer, JPCERT/CC coordinated with Vulncheck Inc. and the developer.
References
| Type | URL | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-007754.html",
"dc:date": "2025-07-02T11:31+09:00",
"dcterms:issued": "2025-07-02T11:31+09:00",
"dcterms:modified": "2025-07-02T11:31+09:00",
"description": "CONPROSYS HMI System (CHS) provided by Contec Co.,Ltd. contains multiple vulnerabilities listed below.\r\n\r\n * Reflected cross-site scripting (CWE-79) - CVE-2025-34080\r\n * Insertion of sensitive information into debugging code (CWE-215) - CVE-2025-34081\r\n\r\nAlex Williams of Converge Technology Solutions reported these vulnerabilities to Vulncheck Inc., and\r\nVulncheck Inc. reported these vulnerabilities to the developer.\r\nBased on the coordination request made by the developer, JPCERT/CC coordinated with Vulncheck Inc. and the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-007754.html",
"sec:cpe": {
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "6.1",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2025-007754",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU92266386/index.html",
"@id": "JVNVU#92266386",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-34080",
"@id": "CVE-2025-34080",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2025-34081",
"@id": "CVE-2025-34081",
"@source": "CVE"
},
{
"#text": "https://cwe.mitre.org/data/definitions/215.html",
"@id": "CWE-215",
"@title": "Insertion of Sensitive Information Into Debugging Code(CWE-215)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
}
JVNDB-2023-002002
Vulnerability from jvndb - Published: 2023-06-01 04:48 - Updated:2024-03-19 09:13
Severity
Summary
Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
Details
CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
* Plaintext storage of a password (CWE-256) - CVE-2023-28713
* Incorrect permission assignment for critical resource (CWE-732) - CVE-2023-28399
* Improper access control (CWE-284) - CVE-2023-28657
* Cross-site scripting (CWE-79) - CVE-2023-28651
* Server-side request forgery (CWE-918)- CVE-2023-28824
* SQL injection (CWE-89) - CVE-2023-29154
* Improper control of interaction frequency (CWE-799) - CVE-2023-2758
Michael Heinzl reported the vulnerabilities listed below to JPCERT/CC, and JPCERT/CC coordinated with the developer.
CVE-2023-28713, CVE-2023-28399, CVE-2023-28657, CVE-2023-28651, CVE-2023-28824, CVE-2023-29154
Tenable, Inc. reported CVE-2023-2758 vulnerability to the developer, and based on the coordination request made by the developer, JPCERT/CC coordinated with Tenable, Inc. and the developer.
References
| Type | URL | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-002002.html",
"dc:date": "2024-03-19T18:13+09:00",
"dcterms:issued": "2023-06-01T13:48+09:00",
"dcterms:modified": "2024-03-19T18:13+09:00",
"description": "CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n\r\n* Plaintext storage of a password (CWE-256) - CVE-2023-28713\r\n* Incorrect permission assignment for critical resource (CWE-732) - CVE-2023-28399\r\n* Improper access control (CWE-284) - CVE-2023-28657\r\n* Cross-site scripting (CWE-79) - CVE-2023-28651\r\n* Server-side request forgery (CWE-918)- CVE-2023-28824\r\n* SQL injection (CWE-89) - CVE-2023-29154\r\n* Improper control of interaction frequency (CWE-799) - CVE-2023-2758\r\n\r\nMichael Heinzl reported the vulnerabilities listed below to JPCERT/CC, and JPCERT/CC coordinated with the developer.\r\nCVE-2023-28713, CVE-2023-28399, CVE-2023-28657, CVE-2023-28651, CVE-2023-28824, CVE-2023-29154\r\n\r\nTenable, Inc. reported CVE-2023-2758 vulnerability to the developer, and based on the coordination request made by the developer, JPCERT/CC coordinated with Tenable, Inc. and the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-002002.html",
"sec:cpe": {
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2023-002002",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU93372935/index.html",
"@id": "JVNVU#93372935",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-28713",
"@id": "CVE-2023-28713",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-28399",
"@id": "CVE-2023-28399",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-28657",
"@id": "CVE-2023-28657",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-28651",
"@id": "CVE-2023-28651",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-28824",
"@id": "CVE-2023-28824",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-29154",
"@id": "CVE-2023-29154",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-2758",
"@id": "CVE-2023-2758",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-2758",
"@id": "CVE-2023-2758",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28399",
"@id": "CVE-2023-28399",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28651",
"@id": "CVE-2023-28651",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28657",
"@id": "CVE-2023-28657",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28713",
"@id": "CVE-2023-28713",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-28824",
"@id": "CVE-2023-28824",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-29154",
"@id": "CVE-2023-29154",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/256.html",
"@id": "CWE-256",
"@title": "Unprotected Storage of Credentials(CWE-256)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/284.html",
"@id": "CWE-284",
"@title": "Improper Access Control(CWE-284)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/732.html",
"@id": "CWE-732",
"@title": "Incorrect Permission Assignment for Critical Resource(CWE-732)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/799.html",
"@id": "CWE-799",
"@title": "Improper Control of Interaction Frequency(CWE-799)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-89",
"@title": "SQL Injection(CWE-89)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/918.html",
"@id": "CWE-918",
"@title": "Server-Side Request Forgery (SSRF)(CWE-918)"
}
],
"title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
}
JVNDB-2023-001774
Vulnerability from jvndb - Published: 2023-05-09 07:09 - Updated:2024-06-27 04:30
Severity
Summary
Multiple vulnerabilities in SolarView Compact
Details
SolarView Compact provided by CONTEC CO.,LTD. contains multiple vulnerabilities listed below.
* Use of hard-coded credentials (CWE-798) - CVE-2023-27512
* OS command injection in the download page (CWE-78) - CVE-2023-27514
* Buffer overflow in the multiple setting pages (CWE-120) - CVE-2023-27518
* OS command injection in the mail setting page (CWE-78) - CVE-2023-27521
* Improper access control in the system date/time setting page (CWE-284) - CVE-2023-27920
CVE-2023-27512, CVE-2023-27514, CVE-2023-27518, CVE-2023-27521
Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
CVE-2023-27920
CONTEC CO.,LTD. reported this vulnerability to JPCERT/CC to notify users of its solutions through JVN.
References
| Type | URL | ||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001774.html",
"dc:date": "2024-06-27T13:30+09:00",
"dcterms:issued": "2023-05-09T16:09+09:00",
"dcterms:modified": "2024-06-27T13:30+09:00",
"description": "SolarView Compact provided by CONTEC CO.,LTD. contains multiple vulnerabilities listed below.\r\n\r\n * Use of hard-coded credentials (CWE-798) - CVE-2023-27512\r\n * OS command injection in the download page (CWE-78) - CVE-2023-27514\r\n * Buffer overflow in the multiple setting pages (CWE-120) - CVE-2023-27518\r\n * OS command injection in the mail setting page (CWE-78) - CVE-2023-27521\r\n * Improper access control in the system date/time setting page (CWE-284) - CVE-2023-27920\r\n\r\nCVE-2023-27512, CVE-2023-27514, CVE-2023-27518, CVE-2023-27521\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.\r\n\r\nCVE-2023-27920\r\nCONTEC CO.,LTD. reported this vulnerability to JPCERT/CC to notify users of its solutions through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001774.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
"@product": "SolarView Compact SV-CPT-MC310F",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2023-001774",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU92106300/index.html",
"@id": "JVNVU#92106300",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27512",
"@id": "CVE-2023-27512",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27514",
"@id": "CVE-2023-27514",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27518",
"@id": "CVE-2023-27518",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27521",
"@id": "CVE-2023-27521",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27920",
"@id": "CVE-2023-27920",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27512",
"@id": "CVE-2023-27512",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27514",
"@id": "CVE-2023-27514",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27518",
"@id": "CVE-2023-27518",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27521",
"@id": "CVE-2023-27521",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27920",
"@id": "CVE-2023-27920",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/120.html",
"@id": "CWE-120",
"@title": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)(CWE-120)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/284.html",
"@id": "CWE-284",
"@title": "Improper Access Control(CWE-284)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/798.html",
"@id": "CWE-798",
"@title": "Use of Hard-coded Credentials(CWE-798)"
}
],
"title": "Multiple vulnerabilities in SolarView Compact"
}
JVNDB-2023-001400
Vulnerability from jvndb - Published: 2023-04-03 07:19 - Updated:2023-04-03 07:19
Severity
Summary
CONPROSYS HMI System(CHS) vulnerable to SQL injection
Details
CONPROSYS HMI System(CHS) provided by Contec Co., Ltd. contains an SQL injection vulnerability (CWE-89, CVE-2023-1658).
Tenable Network Security reported this vulnerability to the developer.
JPCERT/CC coordinated with the reporter and the developer.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001400.html",
"dc:date": "2023-04-03T16:19+09:00",
"dcterms:issued": "2023-04-03T16:19+09:00",
"dcterms:modified": "2023-04-03T16:19+09:00",
"description": "CONPROSYS HMI System(CHS) provided by Contec Co., Ltd. contains an SQL injection vulnerability (CWE-89, CVE-2023-1658).\r\n\r\nTenable Network Security reported this vulnerability to the developer.\r\nJPCERT/CC coordinated with the reporter and the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001400.html",
"sec:cpe": {
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "7.5",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2023-001400",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU92145493/index.html",
"@id": "JVNVU#92145493",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-1658",
"@id": "CVE-2023-1658",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-89",
"@title": "SQL Injection(CWE-89)"
}
],
"title": "CONPROSYS HMI System(CHS) vulnerable to SQL injection"
}
JVNDB-2023-001320
Vulnerability from jvndb - Published: 2023-03-22 04:41 - Updated:2024-06-04 08:00
Severity
Summary
Multiple vulnerabilities in Contec CONPROSYS IoT Gateway products
Details
CONPROSYS IoT Gateway products provided by Contec CO.,LTD. contain multiple vulnerabilities listed below.
* OS Command Injection (CWE-78) - CVE-2023-27917
Network Maintenance page validates input values improperly, resulting in OS command injection.
* Inadequate Encryption Strength (CWE-326) - CVE-2023-27389
Firmware update file contains a firmware image encrypted, which can be decrypted by examining the bundled install script and a little more work.
* Improper Access Control (CWE-284) - CVE-2023-23575
Network Maintenance page should be available only to administrative users, but the device fails to restrict access.
References
| Type | URL | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001320.html",
"dc:date": "2024-06-04T17:00+09:00",
"dcterms:issued": "2023-03-22T13:41+09:00",
"dcterms:modified": "2024-06-04T17:00+09:00",
"description": "CONPROSYS IoT Gateway products provided by Contec CO.,LTD. contain multiple vulnerabilities listed below.\r\n\r\n* OS Command Injection (CWE-78) - CVE-2023-27917\r\nNetwork Maintenance page validates input values improperly, resulting in OS command injection.\r\n* Inadequate Encryption Strength (CWE-326) - CVE-2023-27389\r\nFirmware update file contains a firmware image encrypted, which can be decrypted by examining the bundled install script and a little more work.\r\n* Improper Access Control (CWE-284) - CVE-2023-23575\r\nNetwork Maintenance page should be available only to administrative users, but the device fails to restrict access.",
"link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001320.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:cps-mc341-a1-111_firmware",
"@product": "CPS-MC341-A1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-adsc1-111_firmware",
"@product": "CPS-MC341-ADSC1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-adsc1-931_firmware",
"@product": "CPS-MC341-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-adsc2-111_firmware",
"@product": "CPS-MC341-ADSC2-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-ds1-111_firmware",
"@product": "CPS-MC341-DS1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-ds11-111_firmware",
"@product": "CPS-MC341-DS11-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341-ds2-911_firmware",
"@product": "CPS-MC341-DS2-911",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341g-adsc1-110_firmwar",
"@product": "CPS-MC341G-ADSC1-110",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mc341q-adsc1-111_firmware",
"@product": "CPS-MC341Q-ADSC1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mcs341-ds1-111_firmware",
"@product": "CPS-MCS341-DS1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mcs341-ds1-131_firmware",
"@product": "CPS-MCS341-DS1-131",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mcs341g-ds1-130_firmware",
"@product": "CPS-MCS341G-DS1-130",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mcs341g5-ds1-130_firmware",
"@product": "CPS-MCS341G5-DS1-130",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mcs341q-ds1-131_firmware",
"@product": "CPS-MCS341Q-DS1-131",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mg341-adsc1-111_firmware",
"@product": "CPS-MG341-ADSC1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mg341-adsc1-931_firmware",
"@product": "CPS-MG341-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mg341g-adsc1-111_firmware",
"@product": "CPS-MG341G-ADSC1-111",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mg341g-adsc1-930_firmware",
"@product": "CPS-MG341G-ADSC1-930",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:cps-mg341g5-adsc1-931_firmware",
"@product": "CPS-MG341G5-ADSC1-931",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2023-001320",
"sec:references": [
{
"#text": "http://jvn.jp/en/vu/JVNVU96198617/index.html",
"@id": "JVNVU#96198617",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27917",
"@id": "CVE-2023-27917",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-27389",
"@id": "CVE-2023-27389",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-23575",
"@id": "CVE-2023-23575",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-23575",
"@id": "CVE-2023-23575",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27389",
"@id": "CVE-2023-27389",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-27917",
"@id": "CVE-2023-27917",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/284.html",
"@id": "CWE-284",
"@title": "Improper Access Control(CWE-284)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/326.html",
"@id": "CWE-326",
"@title": "Inadequate Encryption Strength(CWE-326)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
}
],
"title": "Multiple vulnerabilities in Contec CONPROSYS IoT Gateway products"
}
JVNDB-2023-001108
Vulnerability from jvndb - Published: 2023-01-24 04:38 - Updated:2023-01-24 04:38
Severity
Summary
Contec CONPROSYS HMI System (CHS) vulnerable to multiple SQL injections
Details
CONPROSYS HMI System (CHS) provided by CONTEC CO.,LTD. contains multiple SQL injection vulnerabilities (CWE-89).
Mosin from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc., reported these vulnerabilities to Contec Co., Ltd.
Contec Co., Ltd. reported the issues to JPCERT/CC in order to notify the solutions to the users through JVN.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001108.html",
"dc:date": "2023-01-24T13:38+09:00",
"dcterms:issued": "2023-01-24T13:38+09:00",
"dcterms:modified": "2023-01-24T13:38+09:00",
"description": "CONPROSYS HMI System (CHS) provided by CONTEC CO.,LTD. contains multiple SQL injection vulnerabilities (CWE-89).\r\n\r\nMosin from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc., reported these vulnerabilities to Contec Co., Ltd.\r\nContec Co., Ltd. reported the issues to JPCERT/CC in order to notify the solutions to the users through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-001108.html",
"sec:cpe": {
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2023-001108",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU97195023/index.html",
"@id": "JVNVU#97195023",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-22324",
"@id": "CVE-2023-22324",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22324",
"@id": "CVE-2023-22324",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-89",
"@title": "SQL Injection(CWE-89)"
}
],
"title": "Contec CONPROSYS HMI System (CHS) vulnerable to multiple SQL injections"
}
JVNDB-2022-002779
Vulnerability from jvndb - Published: 2022-12-16 04:29 - Updated:2023-01-11 07:55
Severity
Summary
Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)
Details
CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
* OS Command Injection (CWE-78) - CVE-2022-44456
* Use of Default Credentials (CWE-1392) - CVE-2023-22331
* Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334
* Cross-site Scripting (CWE-79) - CVE-2023-22373
* Improper Access Control (CWE-284) - CVE-2023-22339
Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.
References
| Type | URL | ||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002779.html",
"dc:date": "2023-01-11T16:55+09:00",
"dcterms:issued": "2022-12-16T13:29+09:00",
"dcterms:modified": "2023-01-11T16:55+09:00",
"description": "CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n \r\n * OS Command Injection (CWE-78) - CVE-2022-44456\r\n * Use of Default Credentials (CWE-1392) - CVE-2023-22331\r\n * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334\r\n * Cross-site Scripting (CWE-79) - CVE-2023-22373\r\n * Improper Access Control (CWE-284) - CVE-2023-22339\r\n\r\nFloris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002779.html",
"sec:cpe": {
"#text": "cpe:/a:contec:conprosys_hmi_system",
"@product": "CONPROSYS HMI System (CHS)",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "10.0",
"@severity": "Critical",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2022-002779",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU96873821/index.html",
"@id": "JVNVU#96873821",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-44456",
"@id": "CVE-2022-44456",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-22331",
"@id": "CVE-2023-22331",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-22334",
"@id": "CVE-2023-22334",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-22373",
"@id": "CVE-2023-22373",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-22339",
"@id": "CVE-2023-22339",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-44456",
"@id": "CVE-2022-44456",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22331",
"@id": "CVE-2023-22331",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22334",
"@id": "CVE-2023-22334",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22339",
"@id": "CVE-2023-22339",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-22373",
"@id": "CVE-2023-22373",
"@source": "NVD"
},
{
"#text": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-347-03",
"@id": "ICSA-22-347-03",
"@source": "ICS-CERT ADVISORY"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/836.html",
"@id": "CWE-836",
"@title": "Use of Password Hash Instead of Password for Authentication(CWE-836)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/284.html",
"@id": "CWE-284",
"@title": "Improper Access Control(CWE-284)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/1392.html",
"@id": "CWE-1392",
"@title": "Use of Default Credentials(CWE-1392)"
}
],
"title": "Multiple vulnerabilities in Contec CONPROSYS HMI System (CHS)"
}
JVNDB-2022-002770
Vulnerability from jvndb - Published: 2022-12-06 06:08 - Updated:2024-06-04 08:13
Severity
Summary
Contec SolarView Compact vulnerable to cross-site scripting
Details
SolarView Compact provided by Contec Co., Ltd. is PV Measurement System.
SolarView Compact contains a cross-site scripting vulnerability (CWE-79, CVE-2022-44355) in Check Network Communication Page of the product's web server.
As of 2022 December 5, a Proof-of-Concept (PoC) code exploiting this vulnerability has already been made public.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002770.html",
"dc:date": "2024-06-04T17:13+09:00",
"dcterms:issued": "2022-12-06T15:08+09:00",
"dcterms:modified": "2024-06-04T17:13+09:00",
"description": "SolarView Compact provided by Contec Co., Ltd. is PV Measurement System.\r\nSolarView Compact contains a cross-site scripting vulnerability (CWE-79, CVE-2022-44355) in Check Network Communication Page of the product\u0027s web server.\r\n\r\nAs of 2022 December 5, a Proof-of-Concept (PoC) code exploiting this vulnerability has already been made public.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002770.html",
"sec:cpe": {
"#text": "cpe:/o:contec:solarview_compact_firmware",
"@product": "SolarView Compact firmware",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": {
"@score": "5.4",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2022-002770",
"sec:references": [
{
"#text": "http://jvn.jp/en/vu/JVNVU93526386/index.html",
"@id": "JVNVU#93526386",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-44355",
"@id": "CVE-2022-44355",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-44355",
"@id": "CVE-2022-44355",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
}
],
"title": "Contec SolarView Compact vulnerable to cross-site scripting"
}
JVNDB-2022-002346
Vulnerability from jvndb - Published: 2022-09-02 09:08 - Updated:2022-09-02 09:08
Severity
Summary
Multiple vulnerabilities in Contec FLEXLAN FX3000 and FX2000 series
Details
FLEXLAN FX3000 and FX2000 series provided by Contec Co., Ltd. contain multiple vulnerabilities listed below.
* Hidden Functionality (CWE-912) - CVE-2022-36158
* Use of Hard-coded Credentials (CWE-798) - CVE-2022-36159
Thomas J. Knudsen and Samy Younsi of Necrum Security Labs reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
References
| Type | URL | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002346.html",
"dc:date": "2022-09-02T18:08+09:00",
"dcterms:issued": "2022-09-02T18:08+09:00",
"dcterms:modified": "2022-09-02T18:08+09:00",
"description": "FLEXLAN FX3000 and FX2000 series provided by Contec Co., Ltd. contain multiple vulnerabilities listed below.\r\n * Hidden Functionality (CWE-912) - CVE-2022-36158\r\n * Use of Hard-coded Credentials (CWE-798) - CVE-2022-36159\r\n\r\nThomas J. Knudsen and Samy Younsi of Necrum Security Labs reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002346.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:flexlan_fx2000_firmware",
"@product": "FLEXLAN FX2000 firmware",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:flexlan_fx3000_firmware",
"@product": "FLEXLAN FX3000 firmware",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.0",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2022-002346",
"sec:references": [
{
"#text": "http://jvn.jp/en/vu/JVNVU98305100/index.html",
"@id": "JVNVU#98305100",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-36158",
"@id": "CVE-2022-36158",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-36159",
"@id": "CVE-2022-36159",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-36158",
"@id": "CVE-2022-36158",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-36159",
"@id": "CVE-2022-36159",
"@source": "NVD"
},
{
"#text": "https://cwe.mitre.org/data/definitions/798.html",
"@id": "CWE-798",
"@title": "Use of Hard-coded Credentials(CWE-798)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/912.html",
"@id": "CWE-912",
"@title": "Hidden Functionality(CWE-912)"
}
],
"title": "Multiple vulnerabilities in Contec FLEXLAN FX3000 and FX2000 series"
}
JVNDB-2022-002112
Vulnerability from jvndb - Published: 2022-08-03 08:40 - Updated:2024-06-14 06:21
Severity
Summary
CONTEC SolarView Compact vulnerable to insufficient verification in uploading files
Details
SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System.
The image file management page of SolarView Compact contains an insufficient verification vulnerability when uploadi
webray reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.ng files (CWE-20).
References
| Type | URL | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002112.html",
"dc:date": "2024-06-14T15:21+09:00",
"dcterms:issued": "2022-08-03T17:40+09:00",
"dcterms:modified": "2024-06-14T15:21+09:00",
"description": "SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System.\r\nThe image file management page of SolarView Compact contains an insufficient verification vulnerability when uploadi\r\n\r\nwebray reported this vulnerability to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.ng files (CWE-20).",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-002112.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
"@product": "SolarView Compact SV-CPT-MC310F",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": {
"@score": "8.8",
"@severity": "High",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2022-002112",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU93696585/",
"@id": "JVNVU#93696585",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-35239",
"@id": "CVE-2022-35239",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-35239",
"@id": "CVE-2022-35239",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-20",
"@title": "Improper Input Validation(CWE-20)"
}
],
"title": "CONTEC SolarView Compact vulnerable to insufficient verification in uploading files"
}
JVNDB-2022-001923
Vulnerability from jvndb - Published: 2022-05-27 06:28 - Updated:2024-06-20 02:34
Severity
Summary
Multiple vulnerabilities in CONTEC SolarView Compact
Details
SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System. SolarView Compact contains multiple vulnerabilities listed below.
OS command injection (CWE-78) - CVE-2022-29303
Improper validation of input values on the send test mail console of the product's web server may result in OS command injection.
Directory traversal (CWE-23) - CVE-2022-29298
Improper validation of a URL on the download page of the product's web server may allow a remote attacker to view and obtain an arbitrary file.
Information disclosure (CWE-200) - CVE-2022-29302
The hidden page which enables to edit the product's web server contents exists in the product's web server, and a remote attacker to read and/or alter an arbitrary file on the web server via the hidden page.
OS command injection (CWE-78) - CVE-2022-40881
Improper validation of input values on Check Network Communication Page of the product's web server may result in an arbitrary OS command execution.
OS command injection (CWE-78) - CVE-2023-23333
Improper validation of input values on the download page of the product's web server may result in an arbitrary OS command execution.
CVE-2022-29298
Jongheon Yan of S2W Inc reported CONTEC CO., LTD. that the fix for the vulnerability was insufficient in Ver.6.5. CONTEC CO., LTD. and JPCERT/CC updated respective advisories.
References
| Type | URL | ||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-001923.html",
"dc:date": "2024-06-20T11:34+09:00",
"dcterms:issued": "2022-05-27T15:28+09:00",
"dcterms:modified": "2024-06-20T11:34+09:00",
"description": "SolarView Compact provided by CONTEC CO., LTD. is PV Measurement System. SolarView Compact contains multiple vulnerabilities listed below.\r\n\r\nOS command injection (CWE-78) - CVE-2022-29303\r\nImproper validation of input values on the send test mail console of the product\u0027s web server may result in OS command injection.\r\n\r\nDirectory traversal (CWE-23) - CVE-2022-29298\r\nImproper validation of a URL on the download page of the product\u0027s web server may allow a remote attacker to view and obtain an arbitrary file.\r\n\r\nInformation disclosure (CWE-200) - CVE-2022-29302\r\nThe hidden page which enables to edit the product\u0027s web server contents exists in the product\u0027s web server, and a remote attacker to read and/or alter an arbitrary file on the web server via the hidden page.\r\n\r\nOS command injection (CWE-78) - CVE-2022-40881\r\nImproper validation of input values on Check Network Communication Page of the product\u0027s web server may result in an arbitrary OS command execution.\r\n\r\nOS command injection (CWE-78) - CVE-2023-23333\r\nImproper validation of input values on the download page of the product\u0027s web server may result in an arbitrary OS command execution.\r\n\r\nCVE-2022-29298\r\nJongheon Yan of S2W Inc reported CONTEC CO., LTD. that the fix for the vulnerability was insufficient in Ver.6.5. CONTEC CO., LTD. and JPCERT/CC updated respective advisories.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-001923.html",
"sec:cpe": [
{
"#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
"@product": "SolarView Compact SV-CPT-MC310F",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310f_firmware",
"@product": "SolarView Compact SV-CPT-MC310F",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
},
{
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "5.0",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"@version": "2.0"
},
{
"@score": "9.8",
"@severity": "Critical",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2022-001923",
"sec:references": [
{
"#text": "https://jvn.jp/en/vu/JVNVU92327282/index.html",
"@id": "JVNVU#92327282",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-29303",
"@id": "CVE-2022-29303",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-29298",
"@id": "CVE-2022-29298",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-29302",
"@id": "CVE-2022-29302",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-40881",
"@id": "CVE-2022-40881",
"@source": "CVE"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2023-23333",
"@id": "CVE-2023-23333",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29303",
"@id": "CVE-2022-29303",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29298",
"@id": "CVE-2022-29298",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-29302",
"@id": "CVE-2022-29302",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-40881",
"@id": "CVE-2022-40881",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-23333",
"@id": "CVE-2023-23333",
"@source": "NVD"
},
{
"#text": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"@id": "CVE-2022-29303",
"@source": "CISA Known Exploited Vulnerabilities Catalog"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://cwe.mitre.org/data/definitions/23.html",
"@id": "CWE-23",
"@title": "Relative Path Traversal(CWE-23)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-200",
"@title": "Information Exposure(CWE-200)"
}
],
"title": "Multiple vulnerabilities in CONTEC SolarView Compact"
}
JVNDB-2021-000016
Vulnerability from jvndb - Published: 2021-02-19 07:44 - Updated:2021-02-25 06:31
Severity
Summary
Multiple vulnerabilities in SolarView Compact
Details
SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
*Exposure of information through directory listing (CWE-548) - CVE-2021-20656
*Improper access control (CWE-284) - CVE-2021-20657
*OS command injection (CWE-78) - CVE-2021-20658
*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659
*Cross-site scripting (CWE-79) - CVE-2021-20660
*Directory traversal (CWE-23) - CVE-2021-20661
*Missing authentication for critical function (CWE-306) - CVE-2021-20662
*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324
The product uses previous versions of vsfpd and lighttpd with known vulnerabilities.
CVE-2021-20656
Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2021-20657, CVE-2021-20658
Takayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662
Kouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Kouichirou Okada, Katsunari Yoshioka of Yokohama National University reported to IPA that CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323 and CVE-2014-2324 vulnerabilities still exist in the product. JPCERT/CC coordinated with the developer.
References
| Type | URL | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000016.html",
"dc:date": "2021-02-25T15:31+09:00",
"dcterms:issued": "2021-02-19T16:44+09:00",
"dcterms:modified": "2021-02-25T15:31+09:00",
"description": "SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.\r\n\r\n*Exposure of information through directory listing (CWE-548) - CVE-2021-20656\r\n*Improper access control (CWE-284) - CVE-2021-20657\r\n*OS command injection (CWE-78) - CVE-2021-20658\r\n*Unrestricted upload of file with dangerous type (CWE-434) - CVE-2021-20659\r\n*Cross-site scripting (CWE-79) - CVE-2021-20660\r\n*Directory traversal (CWE-23) - CVE-2021-20661\r\n*Missing authentication for critical function (CWE-306) - CVE-2021-20662\r\n*Using components with known vulnerabilities (CWE-1035) - CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323, CVE-2014-2324\r\nThe product uses previous versions of vsfpd and lighttpd with known vulnerabilities.\r\n\r\nCVE-2021-20656\r\nKouichirou Okada, Katsunari Yoshioka of Yokohama National University reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nCVE-2021-20657, CVE-2021-20658\r\nTakayuki Sasak, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nCVE-2021-20659, CVE-2021-20660, CVE-2021-20661, CVE-2021-20662\r\nKouichirou Okada, Takayuki Sasaki, Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nKouichirou Okada, Katsunari Yoshioka of Yokohama National University reported to IPA that CVE-2011-0762, CVE-2011-4362, CVE-2013-4508, CVE-2013-4559, CVE-2013-4560, CVE-2014-2323 and CVE-2014-2324 vulnerabilities still exist in the product. JPCERT/CC coordinated with the developer.",
"link": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-000016.html",
"sec:cpe": {
"#text": "cpe:/o:contec:sv-cpt-mc310_firmware",
"@product": "SolarView Compact SV-CPT-MC310",
"@vendor": "Contec",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "5.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "6.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2021-000016",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN37417423/index.html",
"@id": "JVN#37417423",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0762",
"@id": "CVE-2011-0762",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4362",
"@id": "CVE-2011-4362",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4508",
"@id": "CVE-2013-4508",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4559",
"@id": "CVE-2013-4559",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4560",
"@id": "CVE-2013-4560",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2323",
"@id": "CVE-2014-2323",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2324",
"@id": "CVE-2014-2324",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20656",
"@id": "CVE-2021-20656",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20657",
"@id": "CVE-2021-20657",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20658",
"@id": "CVE-2021-20658",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20659",
"@id": "CVE-2021-20659",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20660",
"@id": "CVE-2021-20660",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20661",
"@id": "CVE-2021-20661",
"@source": "CVE"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20662",
"@id": "CVE-2021-20662",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2011-0762",
"@id": "CVE-2011-0762",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2011-4362",
"@id": "CVE-2011-4362",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4508",
"@id": "CVE-2013-4508",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4559",
"@id": "CVE-2013-4559",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2013-4560",
"@id": "CVE-2013-4560",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2014-2323",
"@id": "CVE-2014-2323",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2014-2324",
"@id": "CVE-2014-2324",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20656",
"@id": "CVE-2021-20656",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20657",
"@id": "CVE-2021-20657",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20658",
"@id": "CVE-2021-20658",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20659",
"@id": "CVE-2021-20659",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20660",
"@id": "CVE-2021-20660",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20661",
"@id": "CVE-2021-20661",
"@source": "NVD"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20662",
"@id": "CVE-2021-20662",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-200",
"@title": "Information Exposure(CWE-200)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-22",
"@title": "Path Traversal(CWE-22)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-264",
"@title": "Permissions(CWE-264)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-78",
"@title": "OS Command Injection(CWE-78)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-79",
"@title": "Cross-site Scripting(CWE-79)"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Multiple vulnerabilities in SolarView Compact"
}
CVE-2026-82789 (GCVE-0-2026-82789)
Vulnerability from cvelistv5 – Published: 2026-09-14 06:44 – Updated: 2026-09-14 15:45
VLAI
EPSS
VEX
Summary
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-14 15:38 UTC
CWE
- CWE-95 - Improper neutralization of directives in dynamically evaluated code ('Eval Injection')
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Contec | CONPROSYS HMI System(CHS) |
Affected:
0 , < 3.8.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82789",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T15:38:44.904489Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T15:45:31.910Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CONPROSYS HMI System(CHS)",
"vendor": "Contec",
"versions": [
{
"lessThan": "3.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper neutralization of directives in dynamically evaluated code (\u0027Eval Injection\u0027) issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-95",
"description": "Improper neutralization of directives in dynamically evaluated code (\u0027Eval Injection\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T06:44:56.367Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf"
},
{
"url": "https://jvn.jp/en/vu/JVNVU96551518/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-82789",
"datePublished": "2026-09-14T06:44:56.367Z",
"dateReserved": "2026-08-31T02:30:58.279Z",
"dateUpdated": "2026-09-14T15:45:31.910Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-46509 (GCVE-0-2023-46509)
Vulnerability from cvelistv5 – Published: 2023-10-27 00:00 – Updated: 2024-09-12 14:13
VLAI
EPSS
VEX
Summary
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
Severity
No CVSS data available.
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-09-10 14:15 UTC
CWE
- n/a
- CWE-94 - Improper Control of Generation of Code ('Code Injection')
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| contec | solarview_compact |
Affected:
0 , ≤ 6.0
(custom)
cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T20:45:42.270Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "solarview_compact",
"vendor": "contec",
"versions": [
{
"lessThanOrEqual": "6.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-46509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T14:15:34.861950Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-09-12T14:13:31.239Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-10-27T20:40:22.919Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-46509",
"datePublished": "2023-10-27T00:00:00.000Z",
"dateReserved": "2023-10-23T00:00:00.000Z",
"dateUpdated": "2024-09-12T14:13:31.239Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-2758 (GCVE-0-2023-2758)
Vulnerability from cvelistv5 – Published: 2023-05-31 14:09 – Updated: 2025-01-09 20:26
VLAI
EPSS
VEX
Title
Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service
Summary
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-01-09 20:25 UTC
CWE
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Contec | CONPROSYS HMI System |
Affected:
0 , ≤ 3.5.2
(custom)
|
Date Public
2023-05-31 14:08
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T06:33:05.476Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.tenable.com/security/research/tra-2023-21"
},
{
"tags": [
"x_transferred"
],
"url": "https://jvn.jp/en/vu/JVNVU93372935/index.html"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-2758",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-09T20:25:29.496343Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-09T20:26:25.295Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CONPROSYS HMI System",
"vendor": "Contec",
"versions": [
{
"lessThanOrEqual": "3.5.2",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"datePublic": "2023-05-31T14:08:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time."
}
],
"value": "A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-799",
"description": "CWE-799",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-05-31T14:09:49.809Z",
"orgId": "5ac1ecc2-367a-4d16-a0b2-35d495ddd0be",
"shortName": "tenable"
},
"references": [
{
"url": "https://www.tenable.com/security/research/tra-2023-21"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93372935/index.html"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Contec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "5ac1ecc2-367a-4d16-a0b2-35d495ddd0be",
"assignerShortName": "tenable",
"cveId": "CVE-2023-2758",
"datePublished": "2023-05-31T14:09:49.809Z",
"dateReserved": "2023-05-17T12:46:36.673Z",
"dateUpdated": "2025-01-09T20:26:25.295Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}