Known vulnerabilities in CONPROSYS HMI System

Vendor: Contec
Software CPE: cpe:2.3:a:contec:conprosys_hmi_system:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting CONPROSYS HMI System CONPROSYS HMI System is affected by 12 known vulnerabilities: 3 high, 2 medium, 7 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112074 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-34040
CWE-22 High
No
No
3.7.7 01.07.2025 SB2025070133
SB2025070135
#VU112072 - Server-Side Request Forgery (SSRF)
CVE-2025-34021
CWE-918 Low
Available
No
3.7.7 01.07.2025 SB2025070117
SB2025070135
#VU76704 - Improper Control of Interaction Frequency
CVE-2023-2758
CWE-799 Low
No
No
3.5.3 31.05.2023 SB2023053133
#VU76703 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-29154
CWE-89 Low
No
No
3.5.3 31.05.2023 SB2023053133
#VU76701 - Server-Side Request Forgery (SSRF)
CVE-2023-28824
CWE-918 Medium
No
No
3.5.3 31.05.2023 SB2023053133
#VU76700 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-28651
CWE-79 Low
No
No
3.5.3 31.05.2023 SB2023053133
#VU76698 - Improper Access Control
CVE-2023-28657
CWE-284 Medium
No
No
3.5.3 31.05.2023 SB2023053133
#VU76696 - Incorrect Permission Assignment for Critical Resource
CVE-2023-28399
CWE-732 Low
No
No
3.5.3 31.05.2023 SB2023053133
#VU76693 - Unprotected Storage of Credentials
CVE-2023-28713
CWE-256 Low
No
No
3.5.3 31.05.2023 SB2023053133
#VU74219 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-1658
CWE-89 High
No
No
3.5.2 31.03.2023 SB2023033102
#VU71414 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-22324
CWE-89 Low
No
No
3.5.1 23.01.2023 SB2023012301
#VU70322 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-44456
CWE-78 High
No
No
3.4.5 14.12.2022 SB2022121423