Impact
Improper neutralization of special elements used in an OS command allows an attacker who can log into the CONPROSYS PAC Series to execute arbitrary system commands. This flaw can be leveraged to gain full control of the device, exfiltrate data, or disrupt services, thereby compromising confidentiality, integrity, and availability. The weakness is an OS command injection, classified as CWE‑78.
Affected Systems
The vulnerability affects Contec Co., Ltd. products PCS341[][]‑DS1‑1201 and the Integrated Type CPS‑PC341[][]‑*-9201. No specific firmware version information is provided, so all current models in use should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the EPSS score of 1% suggests a low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to require authenticated access, as an attacker must log into the device to supply the malicious input. Once authenticated, the attacker can run arbitrary OS commands.
OpenCVE Enrichment