contec kayıtları
contec üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,2
- Silahlaştırılmış
- 2 · %4,3
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %6,5
- Yayından KEV’e ortanca
- 427 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-798 Use of Hard-coded Credentials2
- CWE-284 Improper Access Control2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2022-29303Silahlaştırılmış | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.contec · sv-cpt-mc310 firmware · CWE-78 | Kritik9,8 | KEV | %98,0 | 12 May 2022 |
69Bu hafta | CVE-2023-23333Silahlaştırılmış | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricticontec · solarview compact firmware · CWE-77 | Kritik9,8 | — | %99,3 | 6 Şub 2023 |
60Bu hafta | CVE-2022-44456İstismar yok | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server wcontec · conprosys hmi system · CWE-78 | Kritik9,8 | — | %69,9 | 18 Ara 2022 |
54Planlayın | CVE-2023-29919Kavram kanıtı | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Kritik9,1 | — | %60,2 | 22 May 2023 |
48Planlayın | CVE-2022-40881Kavram kanıtı | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpcontec · solarview compact firmware · CWE-77 | Kritik9,8 | — | %30,1 | 17 Kas 2022 |
44Planlayın | CVE-2022-29298Kavram kanıtı | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.contec · sv-cpt-mc310 firmware · CWE-22 | Yüksek7,5 | — | %46,8 | 12 May 2022 |
40Planlayın | CVE-2023-29154İstismar yok | SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-89 | Yüksek7,2 | — | %41,4 | 31 May 2023 |
40Planlayın | CVE-2021-20658İstismar yok | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspeccontec · sv-cpt-mc310 firmware · CWE-78 | Kritik9,8 | — | %3,7 | 24 Şub 2021 |
40Planlayın | CVE-2022-31374İstismar yok | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via acontec · sv-cpt-mc310 firmware · CWE-434 | Kritik9,8 | — | %2,4 | 21 Haz 2022 |
39İzleyin | CVE-2022-44354İstismar yok | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.contec · solarview compact firmware · CWE-434 | Kritik9,8 | — | %1,5 | 29 Kas 2022 |
39İzleyin | CVE-2023-46509İstismar yok | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.contec · solarview compact firmware · CWE-94 | Kritik9,8 | — | %0,8 | 27 Eki 2023 |
38İzleyin | CVE-2023-28651İstismar yok | Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-79 | Orta4,8 | — | %62,4 | 31 May 2023 |
38İzleyin | CVE-2021-20660İstismar yok | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via ucontec · sv-cpt-mc310 firmware · CWE-79 | Orta6,1 | — | %47,2 | 24 Şub 2021 |
36İzleyin | CVE-2021-20659İstismar yok | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.contec · sv-cpt-mc310 firmware · CWE-434 | Yüksek8,8 | — | %2,1 | 24 Şub 2021 |
36İzleyin | CVE-2023-27917İstismar yok | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenancontec · cps-mg341-adsc1-111 firmware · CWE-78 | Yüksek8,8 | — | %1,9 | 11 Nis 2023 |
36İzleyin | CVE-2023-27514İstismar yok | OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versicontec · sv-cpt-mc310f firmware · CWE-78 | Yüksek8,8 | — | %1,9 | 22 May 2023 |
36İzleyin | CVE-2023-27521İstismar yok | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-78 | Yüksek8,8 | — | %1,9 | 22 May 2023 |
35İzleyin | CVE-2023-27518İstismar yok | Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F vcontec · sv-cpt-mc310f firmware · CWE-120 | Yüksek8,8 | — | %1,5 | 22 May 2023 |
35İzleyin | CVE-2022-35239İstismar yok | The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an incontec · sv-cpt-mc310f firmware · CWE-20 | Yüksek8,8 | — | %1,4 | 16 Ağu 2022 |
35İzleyin | CVE-2022-36159İstismar yok | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.contec · fxa3000 firmware · CWE-798 | Yüksek8,8 | — | %1,0 | 26 Eyl 2022 |
35İzleyin | CVE-2023-28657İstismar yok | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-862 | Yüksek8,8 | — | %0,7 | 31 May 2023 |
33İzleyin | CVE-2021-20661İstismar yok | Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary filecontec · sv-cpt-mc310 firmware · CWE-22 | Yüksek8,1 | — | %2,5 | 24 Şub 2021 |
32İzleyin | CVE-2022-36158İstismar yok | Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actocontec · fxa3000 firmware · CWE-425 | Yüksek8,0 | — | %1,6 | 26 Eyl 2022 |
32İzleyin | CVE-2023-28713İstismar yok | Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.contec · conprosys hmi system · CWE-312 | Yüksek8,1 | — | %0,4 | 31 May 2023 |
31İzleyin | CVE-2023-40924Kavram kanıtı | SolarView Compact < 6.00 is vulnerable to Directory Traversal.contec · solarview compact firmware · CWE-22 | Yüksek7,5 | — | %3,2 | 8 Eyl 2023 |
- CVE-2022-2930398Hemen
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98contec · sv-cpt-mc310 firmware12 May 2022
- CVE-2023-2333369Bu hafta
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricti
KritikCVSS 9,8SilahlaştırılmışEPSS %99contec · solarview compact firmware6 Şub 2023
- CVE-2022-4445660Bu hafta
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server w
KritikCVSS 9,8İstismar yokEPSS %70contec · conprosys hmi system18 Ara 2022
- CVE-2023-2991954Planlayın
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
KritikCVSS 9,1Kavram kanıtıEPSS %60contec · solarview compact firmware22 May 2023
- CVE-2022-4088148Planlayın
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
KritikCVSS 9,8Kavram kanıtıEPSS %30contec · solarview compact firmware17 Kas 2022
- CVE-2022-2929844Planlayın
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
YüksekCVSS 7,5Kavram kanıtıEPSS %47contec · sv-cpt-mc310 firmware12 May 2022
- CVE-2023-2915440Planlayın
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.
YüksekCVSS 7,2İstismar yokEPSS %41contec · conprosys hmi system31 May 2023
- CVE-2021-2065840Planlayın
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspec
KritikCVSS 9,8İstismar yokEPSS %4contec · sv-cpt-mc310 firmware24 Şub 2021
- CVE-2022-3137440Planlayın
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a
KritikCVSS 9,8İstismar yokEPSS %2contec · sv-cpt-mc310 firmware21 Haz 2022
- CVE-2022-4435439İzleyin
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
KritikCVSS 9,8İstismar yokEPSS %1contec · solarview compact firmware29 Kas 2022
- CVE-2023-4650939İzleyin
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
KritikCVSS 9,8İstismar yokEPSS %1contec · solarview compact firmware27 Eki 2023
- CVE-2023-2865138İzleyin
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
OrtaCVSS 4,8İstismar yokEPSS %62contec · conprosys hmi system31 May 2023
- CVE-2021-2066038İzleyin
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via u
OrtaCVSS 6,1İstismar yokEPSS %47contec · sv-cpt-mc310 firmware24 Şub 2021
- CVE-2021-2065936İzleyin
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors.
YüksekCVSS 8,8İstismar yokEPSS %2contec · sv-cpt-mc310 firmware24 Şub 2021
- CVE-2023-2791736İzleyin
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenan
YüksekCVSS 8,8İstismar yokEPSS %2contec · cps-mg341-adsc1-111 firmware11 Nis 2023
- CVE-2023-2751436İzleyin
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versi
YüksekCVSS 8,8İstismar yokEPSS %2contec · sv-cpt-mc310f firmware22 May 2023
- CVE-2023-2752136İzleyin
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
YüksekCVSS 8,8İstismar yokEPSS %2contec · sv-cpt-mc310f firmware22 May 2023
- CVE-2023-2751835İzleyin
Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F v
YüksekCVSS 8,8İstismar yokEPSS %2contec · sv-cpt-mc310f firmware22 May 2023
- CVE-2022-3523935İzleyin
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an in
YüksekCVSS 8,8İstismar yokEPSS %1contec · sv-cpt-mc310f firmware16 Ağu 2022
- CVE-2022-3615935İzleyin
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow.
YüksekCVSS 8,8İstismar yokEPSS %1contec · fxa3000 firmware26 Eyl 2022
- CVE-2023-2865735İzleyin
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
YüksekCVSS 8,8İstismar yokEPSS %1contec · conprosys hmi system31 May 2023
- CVE-2021-2066133İzleyin
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary file
YüksekCVSS 8,1İstismar yokEPSS %2contec · sv-cpt-mc310 firmware24 Şub 2021
- CVE-2022-3615832İzleyin
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious acto
YüksekCVSS 8,0İstismar yokEPSS %2contec · fxa3000 firmware26 Eyl 2022
- CVE-2023-2871332İzleyin
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
YüksekCVSS 8,1İstismar yokEPSS %0contec · conprosys hmi system31 May 2023
- CVE-2023-4092431İzleyin
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
YüksekCVSS 7,5Kavram kanıtıEPSS %3contec · solarview compact firmware8 Eyl 2023