CVE-2023-28824

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 918

Summary

CVE-2023-28824 is a server-side request forgery vulnerability affectting versions of the CONPROSYS HMI System (CHS) below 3.5.3. This issue allows an administrative user with access to the product to bypass database restrictions on the query setting page and connect to unintended databases. This can potentially lead to unauthorized data access or manipulation. Organizations using CHS are advised to update to the latest version to mitigate this risk. Unpatched systems may be susceptible to data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share