Impact
A reflected or stored cross‑site scripting flaw in Contec CONPROSYS PAC Series devices allows an attacker to inject and execute arbitrary scripts in the web browser of a user who is logged into the device’s interface. The vulnerability is a classic CWE‑79 XSS weakness that can lead to session hijacking, data theft, or interface defacement. The impact is limited to the authenticated web session of the user who loads the compromised page.
Affected Systems
Contec Co., Ltd. products affected are the Configurable type CPS‑PCS341[][]‑DS1‑1201 and the Integrated Type CPS‑PC341[][]‑*-9201. No specific firmware or software version numbers are listed, but the vulnerability applies to the current releases of these device families mentioned in the vendor advisory.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium‑severity flaw, and the EPSS score is not available, so the current likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. Attackers likely exploit it by sending a crafted HTTP request to the device’s web UI while an authenticated user is browsing the interface; the flaw does not require local privileges and can be triggered remotely over the network.
OpenCVE Enrichment