Записи Contec
46 опубликованных записей вендора contec.
Профиль для исследователя
- Попали в KEV
- 1 · 2,2 %
- С эксплойтом
- 2 · 4,3 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 6,5 %
- Медиана: публикация → KEV
- 427 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-798 Use of Hard-coded Credentials2
- CWE-284 Improper Access Control2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
46 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2022-29303Готовый эксплойт | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.contec · sv-cpt-mc310 firmware · CWE-78 | Критическая9,8 | KEV | 98,0 % | 12 мая 2022 г. |
69На этой неделе | CVE-2023-23333Готовый эксплойт | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricticontec · solarview compact firmware · CWE-77 | Критическая9,8 | — | 99,3 % | 6 февр. 2023 г. |
60На этой неделе | CVE-2022-44456Эксплойта нет | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server wcontec · conprosys hmi system · CWE-78 | Критическая9,8 | — | 69,9 % | 18 дек. 2022 г. |
54В плане | CVE-2023-29919Proof of concept | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Критическая9,1 | — | 60,2 % | 22 мая 2023 г. |
48В плане | CVE-2022-40881Proof of concept | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpcontec · solarview compact firmware · CWE-77 | Критическая9,8 | — | 30,1 % | 17 нояб. 2022 г. |
44В плане | CVE-2022-29298Proof of concept | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.contec · sv-cpt-mc310 firmware · CWE-22 | Высокая7,5 | — | 46,8 % | 12 мая 2022 г. |
40В плане | CVE-2023-29154Эксплойта нет | SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-89 | Высокая7,2 | — | 41,4 % | 31 мая 2023 г. |
40В плане | CVE-2021-20658Эксплойта нет | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspeccontec · sv-cpt-mc310 firmware · CWE-78 | Критическая9,8 | — | 3,7 % | 24 февр. 2021 г. |
40В плане | CVE-2022-31374Эксплойта нет | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via acontec · sv-cpt-mc310 firmware · CWE-434 | Критическая9,8 | — | 2,4 % | 21 июн. 2022 г. |
39Наблюдать | CVE-2022-44354Эксплойта нет | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.contec · solarview compact firmware · CWE-434 | Критическая9,8 | — | 1,6 % | 29 нояб. 2022 г. |
39Наблюдать | CVE-2023-46509Эксплойта нет | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.contec · solarview compact firmware · CWE-94 | Критическая9,8 | — | 0,8 % | 27 окт. 2023 г. |
38Наблюдать | CVE-2023-28651Эксплойта нет | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-79 | Средняя4,8 | — | 62,4 % | 31 мая 2023 г. |
38Наблюдать | CVE-2021-20660Эксплойта нет | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via ucontec · sv-cpt-mc310 firmware · CWE-79 | Средняя6,1 | — | 47,2 % | 24 февр. 2021 г. |
36Наблюдать | CVE-2021-20659Эксплойта нет | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.contec · sv-cpt-mc310 firmware · CWE-434 | Высокая8,8 | — | 2,1 % | 24 февр. 2021 г. |
36Наблюдать | CVE-2023-27917Эксплойта нет | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenancontec · cps-mg341-adsc1-111 firmware · CWE-78 | Высокая8,8 | — | 1,9 % | 11 апр. 2023 г. |
36Наблюдать | CVE-2023-27514Эксплойта нет | OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versicontec · sv-cpt-mc310f firmware · CWE-78 | Высокая8,8 | — | 1,9 % | 22 мая 2023 г. |
36Наблюдать | CVE-2023-27521Эксплойта нет | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-78 | Высокая8,8 | — | 1,9 % | 22 мая 2023 г. |
35Наблюдать | CVE-2023-27518Эксплойта нет | Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-120 | Высокая8,8 | — | 1,5 % | 22 мая 2023 г. |
35Наблюдать | CVE-2022-35239Эксплойта нет | The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an incontec · sv-cpt-mc310f firmware · CWE-20 | Высокая8,8 | — | 1,4 % | 16 авг. 2022 г. |
35Наблюдать | CVE-2022-36159Эксплойта нет | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.contec · fxa3000 firmware · CWE-798 | Высокая8,8 | — | 1,0 % | 26 сент. 2022 г. |
35Наблюдать | CVE-2023-28657Эксплойта нет | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-862 | Высокая8,8 | — | 0,7 % | 31 мая 2023 г. |
33Наблюдать | CVE-2021-20661Эксплойта нет | Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary filecontec · sv-cpt-mc310 firmware · CWE-22 | Высокая8,1 | — | 2,5 % | 24 февр. 2021 г. |
32Наблюдать | CVE-2022-36158Эксплойта нет | Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actocontec · fxa3000 firmware · CWE-425 | Высокая8,0 | — | 1,6 % | 26 сент. 2022 г. |
32Наблюдать | CVE-2023-28713Эксплойта нет | Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-312 | Высокая8,1 | — | 0,4 % | 31 мая 2023 г. |
31Наблюдать | CVE-2023-40924Proof of concept | SolarView Compact < 6.00 is vulnerable to Directory Traversal.contec · solarview compact firmware · CWE-22 | Высокая7,5 | — | 3,2 % | 8 сент. 2023 г. |
- CVE-2022-2930398Срочно
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %contec · sv-cpt-mc310 firmware12 мая 2022 г.
- CVE-2023-2333369На этой неделе
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricti
КритическаяCVSS 9,8Готовый эксплойтEPSS 99 %contec · solarview compact firmware6 февр. 2023 г.
- CVE-2022-4445660На этой неделе
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server w
КритическаяCVSS 9,8Эксплойта нетEPSS 70 %contec · conprosys hmi system18 дек. 2022 г.
- CVE-2023-2991954В плане
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
КритическаяCVSS 9,1Proof of conceptEPSS 60 %contec · solarview compact firmware22 мая 2023 г.
- CVE-2022-4088148В плане
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
КритическаяCVSS 9,8Proof of conceptEPSS 30 %contec · solarview compact firmware17 нояб. 2022 г.
- CVE-2022-2929844В плане
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %contec · sv-cpt-mc310 firmware12 мая 2022 г.
- CVE-2023-2915440В плане
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.
ВысокаяCVSS 7,2Эксплойта нетEPSS 41 %contec · conprosys hmi system31 мая 2023 г.
- CVE-2021-2065840В плане
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspec
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %contec · sv-cpt-mc310 firmware24 февр. 2021 г.
- CVE-2022-3137440В плане
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %contec · sv-cpt-mc310 firmware21 июн. 2022 г.
- CVE-2022-4435439Наблюдать
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %contec · solarview compact firmware29 нояб. 2022 г.
- CVE-2023-4650939Наблюдать
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %contec · solarview compact firmware27 окт. 2023 г.
- CVE-2023-2865138Наблюдать
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
СредняяCVSS 4,8Эксплойта нетEPSS 62 %contec · conprosys hmi system31 мая 2023 г.
- CVE-2021-2066038Наблюдать
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via u
СредняяCVSS 6,1Эксплойта нетEPSS 47 %contec · sv-cpt-mc310 firmware24 февр. 2021 г.
- CVE-2021-2065936Наблюдать
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %contec · sv-cpt-mc310 firmware24 февр. 2021 г.
- CVE-2023-2791736Наблюдать
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenan
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %contec · cps-mg341-adsc1-111 firmware11 апр. 2023 г.
- CVE-2023-2751436Наблюдать
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %contec · sv-cpt-mc310f firmware22 мая 2023 г.
- CVE-2023-2752136Наблюдать
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %contec · sv-cpt-mc310f firmware22 мая 2023 г.
- CVE-2023-2751835Наблюдать
Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %contec · sv-cpt-mc310f firmware22 мая 2023 г.
- CVE-2022-3523935Наблюдать
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %contec · sv-cpt-mc310f firmware16 авг. 2022 г.
- CVE-2022-3615935Наблюдать
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %contec · fxa3000 firmware26 сент. 2022 г.
- CVE-2023-2865735Наблюдать
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %contec · conprosys hmi system31 мая 2023 г.
- CVE-2021-2066133Наблюдать
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary file
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %contec · sv-cpt-mc310 firmware24 февр. 2021 г.
- CVE-2022-3615832Наблюдать
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious acto
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %contec · fxa3000 firmware26 сент. 2022 г.
- CVE-2023-2871332Наблюдать
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %contec · conprosys hmi system31 мая 2023 г.
- CVE-2023-4092431Наблюдать
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %contec · solarview compact firmware8 сент. 2023 г.