Impact
A cross‑site scripting (XSS) flaw in CONPROSYS nano Series allows an attacker to inject and run arbitrary client‑side scripts within the browsers of authenticated users. This could lead to session hijacking, credential theft, or execution of malicious actions on behalf of the logged‑in user. The weakness is a classic client‑side injection problem (CWE‑79).
Affected Systems
Contec Co., Ltd. products including the Programmable Remote I/O Coupler Unit (‑S1‑041, the Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN‑EOB471EI‑[]1, and the Remote I/O Coupler Unit (Server Type) CPSN‑MCB271‑*. No specific firmware or software revision numbers are listed beyond these model identifiers.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, though the Exact Public Score Scale (EPSS) is not available, suggesting limited data on exploitation likelihood. The flaw is not listed in the CISA KEV catalog, so no known active exploitation campaigns are documented. The likely attack vector requires the attacker to have access to the device’s web management interface, typically through an authenticated session. Because the vulnerability is confined to the user’s browser, it affects confidentiality and integrity of user data and can lead to privilege escalation if the attacker can execute scripts that alter stored settings or trigger privileged operations.
OpenCVE Enrichment