Impact
An information disclosure vulnerability exists in the CONPROSYS PAC Series when a specific URL is accessed, enabling a remote unauthenticated attacker to retrieve the directory listing. The flaw results from an improper configuration that allows directory listing on the product’s web interface potentially sensitive configuration files, compromising confidentiality.
Affected Systems
Affected vendors and products include Contec Co., Ltd., with the Configurable type CPS-PCS341[][]-DS1-1201 and Integrated Type CPS-PC341[][]-*-9201. The specific firmware or software versions affected are not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 5.3 categorizes the vulnerability as moderate severity. No publicly known exploits are listed and the EPSS score is unavailable, so the exploitation likelihood appears low. However, the remote, unauthenticated nature of the issue means any network‑connected user could enumerate files without credentials. The vulnerability does not provide code execution or privilege escalation, but the exposed data could assist in further attacks.
OpenCVE Enrichment