Contec records
46 published records for vendor contec.
Researcher profile
- Entered KEV
- 1 · 2.2%
- Weaponized
- 2 · 4.3%
- Pre-auth RCE
- 7
- With a fix record
- 6.5%
- Median publish → KEV
- 427 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-798 Use of Hard-coded Credentials2
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2022-29303Weaponized | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.contec · sv-cpt-mc310 firmware · CWE-78 | Critical9.8 | KEV | 98.0% | May 12, 2022 |
69This week | CVE-2023-23333Weaponized | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricticontec · solarview compact firmware · CWE-77 | Critical9.8 | — | 99.3% | Feb 6, 2023 |
60This week | CVE-2022-44456No exploit | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server wcontec · conprosys hmi system · CWE-78 | Critical9.8 | — | 69.9% | Dec 18, 2022 |
54Plan | CVE-2023-29919Proof of concept | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Critical9.1 | — | 60.2% | May 22, 2023 |
48Plan | CVE-2022-40881Proof of concept | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpcontec · solarview compact firmware · CWE-77 | Critical9.8 | — | 30.1% | Nov 17, 2022 |
44Plan | CVE-2022-29298Proof of concept | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.contec · sv-cpt-mc310 firmware · CWE-22 | High7.5 | — | 46.8% | May 12, 2022 |
40Plan | CVE-2023-29154No exploit | SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-89 | High7.2 | — | 41.4% | May 31, 2023 |
40Plan | CVE-2021-20658No exploit | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspeccontec · sv-cpt-mc310 firmware · CWE-78 | Critical9.8 | — | 3.7% | Feb 24, 2021 |
40Plan | CVE-2022-31374No exploit | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via acontec · sv-cpt-mc310 firmware · CWE-434 | Critical9.8 | — | 2.4% | Jun 21, 2022 |
39Monitor | CVE-2022-44354No exploit | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.contec · solarview compact firmware · CWE-434 | Critical9.8 | — | 1.6% | Nov 29, 2022 |
39Monitor | CVE-2023-46509No exploit | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.contec · solarview compact firmware · CWE-94 | Critical9.8 | — | 0.8% | Oct 27, 2023 |
38Monitor | CVE-2023-28651No exploit | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-79 | Medium4.8 | — | 62.4% | May 31, 2023 |
38Monitor | CVE-2021-20660No exploit | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via ucontec · sv-cpt-mc310 firmware · CWE-79 | Medium6.1 | — | 47.2% | Feb 24, 2021 |
36Monitor | CVE-2021-20659No exploit | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.contec · sv-cpt-mc310 firmware · CWE-434 | High8.8 | — | 2.1% | Feb 24, 2021 |
36Monitor | CVE-2023-27917No exploit | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenancontec · cps-mg341-adsc1-111 firmware · CWE-78 | High8.8 | — | 1.9% | Apr 11, 2023 |
36Monitor | CVE-2023-27514No exploit | OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versicontec · sv-cpt-mc310f firmware · CWE-78 | High8.8 | — | 1.9% | May 22, 2023 |
36Monitor | CVE-2023-27521No exploit | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-78 | High8.8 | — | 1.9% | May 22, 2023 |
35Monitor | CVE-2023-27518No exploit | Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-120 | High8.8 | — | 1.5% | May 22, 2023 |
35Monitor | CVE-2022-35239No exploit | The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an incontec · sv-cpt-mc310f firmware · CWE-20 | High8.8 | — | 1.4% | Aug 16, 2022 |
35Monitor | CVE-2022-36159No exploit | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.contec · fxa3000 firmware · CWE-798 | High8.8 | — | 1.0% | Sep 26, 2022 |
35Monitor | CVE-2023-28657No exploit | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-862 | High8.8 | — | 0.7% | May 31, 2023 |
33Monitor | CVE-2021-20661No exploit | Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary filecontec · sv-cpt-mc310 firmware · CWE-22 | High8.1 | — | 2.5% | Feb 24, 2021 |
32Monitor | CVE-2022-36158No exploit | Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actocontec · fxa3000 firmware · CWE-425 | High8.0 | — | 1.6% | Sep 26, 2022 |
32Monitor | CVE-2023-28713No exploit | Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-312 | High8.1 | — | 0.4% | May 31, 2023 |
31Monitor | CVE-2023-40924Proof of concept | SolarView Compact < 6.00 is vulnerable to Directory Traversal.contec · solarview compact firmware · CWE-22 | High7.5 | — | 3.2% | Sep 8, 2023 |
- CVE-2022-2930398Now
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%contec · sv-cpt-mc310 firmwareMay 12, 2022
- CVE-2023-2333369This week
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricti
CriticalCVSS 9.8WeaponizedEPSS 99%contec · solarview compact firmwareFeb 6, 2023
- CVE-2022-4445660This week
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server w
CriticalCVSS 9.8No exploitEPSS 70%contec · conprosys hmi systemDec 18, 2022
- CVE-2023-2991954Plan
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
CriticalCVSS 9.1Proof of conceptEPSS 60%contec · solarview compact firmwareMay 22, 2023
- CVE-2022-4088148Plan
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
CriticalCVSS 9.8Proof of conceptEPSS 30%contec · solarview compact firmwareNov 17, 2022
- CVE-2022-2929844Plan
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
HighCVSS 7.5Proof of conceptEPSS 47%contec · sv-cpt-mc310 firmwareMay 12, 2022
- CVE-2023-2915440Plan
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.
HighCVSS 7.2No exploitEPSS 41%contec · conprosys hmi systemMay 31, 2023
- CVE-2021-2065840Plan
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspec
CriticalCVSS 9.8No exploitEPSS 4%contec · sv-cpt-mc310 firmwareFeb 24, 2021
- CVE-2022-3137440Plan
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a
CriticalCVSS 9.8No exploitEPSS 2%contec · sv-cpt-mc310 firmwareJun 21, 2022
- CVE-2022-4435439Monitor
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
CriticalCVSS 9.8No exploitEPSS 2%contec · solarview compact firmwareNov 29, 2022
- CVE-2023-4650939Monitor
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
CriticalCVSS 9.8No exploitEPSS 1%contec · solarview compact firmwareOct 27, 2023
- CVE-2023-2865138Monitor
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
MediumCVSS 4.8No exploitEPSS 62%contec · conprosys hmi systemMay 31, 2023
- CVE-2021-2066038Monitor
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via u
MediumCVSS 6.1No exploitEPSS 47%contec · sv-cpt-mc310 firmwareFeb 24, 2021
- CVE-2021-2065936Monitor
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.
HighCVSS 8.8No exploitEPSS 2%contec · sv-cpt-mc310 firmwareFeb 24, 2021
- CVE-2023-2791736Monitor
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenan
HighCVSS 8.8No exploitEPSS 2%contec · cps-mg341-adsc1-111 firmwareApr 11, 2023
- CVE-2023-2751436Monitor
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versi
HighCVSS 8.8No exploitEPSS 2%contec · sv-cpt-mc310f firmwareMay 22, 2023
- CVE-2023-2752136Monitor
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
HighCVSS 8.8No exploitEPSS 2%contec · sv-cpt-mc310f firmwareMay 22, 2023
- CVE-2023-2751835Monitor
Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
HighCVSS 8.8No exploitEPSS 2%contec · sv-cpt-mc310f firmwareMay 22, 2023
- CVE-2022-3523935Monitor
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an in
HighCVSS 8.8No exploitEPSS 1%contec · sv-cpt-mc310f firmwareAug 16, 2022
- CVE-2022-3615935Monitor
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.
HighCVSS 8.8No exploitEPSS 1%contec · fxa3000 firmwareSep 26, 2022
- CVE-2023-2865735Monitor
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
HighCVSS 8.8No exploitEPSS 1%contec · conprosys hmi systemMay 31, 2023
- CVE-2021-2066133Monitor
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary file
HighCVSS 8.1No exploitEPSS 2%contec · sv-cpt-mc310 firmwareFeb 24, 2021
- CVE-2022-3615832Monitor
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious acto
HighCVSS 8.0No exploitEPSS 2%contec · fxa3000 firmwareSep 26, 2022
- CVE-2023-2871332Monitor
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
HighCVSS 8.1No exploitEPSS 0%contec · conprosys hmi systemMay 31, 2023
- CVE-2023-4092431Monitor
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
HighCVSS 7.5Proof of conceptEPSS 3%contec · solarview compact firmwareSep 8, 2023