Impact
This vulnerability is a reflected or stored cross‑site scripting flaw in the CONPROSYS PAC Series web interface. An attacker can inject arbitrary scripts that will execute in the browser of a user who is authenticated to the device. The impact is limited to the web browser context; it does not grant direct device control or persistent code execution on the device, but can be used for phishing, credential theft, or lateral movement by sidestepping authentication within the victim’s session.
Affected Systems
The devices impacted are Contec Co., Ltd. models listed as Configurable Type CPS‑PCS341[][]‑DS1‑1201 and Integrated Type CPS‑PC341[][]‑*-9201. The vendor advisory indicates the flaw applies to current releases of these families, though no specific firmware revision numbers are provided.
Risk and Exploitability
The CVSS score of 5.1 identifies the flaw as medium severity. The EPSS score below 1% indicates a low probability of exploitation, and the vulnerability is not included in CISA's KEV catalog. Based on the description, the attacker can craft a malicious HTTP request targeting the device’s web UI while the victim is logged in; the flaw does not require local privileges and can be triggered remotely across the network.
OpenCVE Enrichment