Contec
contec
46 CVEs • 53 products
Products (53)
Click to collapseToggle
Products (53)
Click to collapse
CVEs (46)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7....Show more |
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue aff...Show more |
1Contec 1Solarview Compact Firmware Nov 21, 2024 Oct 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. |
SolarView Compact < 6.00 is vulnerable to Directory Traversal. |
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially...Show more |
Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may bypass the database restriction set...Show more |
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affe...Show more |
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As a result, information...Show more |
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege configures specially crafted settings, an ar...Show more |
Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the affected product is ins...Show more |
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJan 31, 2025 May 23, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJan 31, 2025 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an ar...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJan 31, 2025 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute arbi...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJan 16, 2025 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbit...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareNov 21, 2024 May 23, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, which may allow a remote authenticated attacker to login the affected produ...Show more |
1Contec 1Solarview Compact Firmware Jan 17, 2025 May 23, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. |
1Contec 19Cps Mc341 A1 111 Firmware Cps Mc341 Adsc1 111 FirmwareCps Mc341 Adsc1 931 Firmware+16 moreFeb 10, 2025 Apr 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected pro...Show more |
1Contec 19Cps Mc341 A1 111 Firmware Cps Mc341 Adsc1 111 FirmwareCps Mc341 Adsc1 931 Firmware+16 moreFeb 10, 2025 Apr 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file, alter the informat...Show more |
1Contec 19Cps Mc341 A1 111 Firmware Cps Mc341 Adsc1 111 FirmwareCps Mc341 Adsc1 931 Firmware+16 moreFeb 11, 2025 Apr 11, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network i...Show more |