Show filters
54 Total Results
Displaying 1-10 of 54
Sort by:
Attacker Value
Very High
CVE-2023-23333
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
2
Attacker Value
Unknown
CVE-2025-0683
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text
patient data to a hard-coded public IP address when a patient is hooked
up to the monitor. This could lead to a leakage of confidential patient
data to any device with that IP address or an attacker in a
machine-in-the-middle scenario.
0
Attacker Value
Unknown
CVE-2025-0626
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor being able to upload and overwrite files on the device.
0
Attacker Value
Unknown
CVE-2024-12248
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
0
Attacker Value
Unknown
CVE-2023-46509
Disclosure Date: October 27, 2023 (last updated November 01, 2023)
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
0
Attacker Value
Unknown
CVE-2023-40924
Disclosure Date: September 08, 2023 (last updated October 08, 2023)
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
0
Attacker Value
Unknown
CVE-2023-29154
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page.
0
Attacker Value
Unknown
CVE-2023-28824
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Server-side request forgery vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may bypass the database restriction set on the query setting page, and connect to a user unintended database.
0
Attacker Value
Unknown
CVE-2023-28713
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.
0
Attacker Value
Unknown
CVE-2023-28657
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As a result, information regarding the product may be obtained and/or altered by the user.
0