Description
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
Published: 2026-09-14
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft via Physical Access
Action: Apply Fix
AI Analysis

Impact

Plaintext passwords are stored in the CONPROSYS nano Series firmware, allowing an attacker who physically reaches the device to read the credentials and compromise access to the remote I/O units. The flaw is a weakness in password storage (CWE-256) that gives direct exposure of secret information.

Affected Systems

All Contec CPSN models are affected, including the Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041, the Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1, and the Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. No specific firmware or hardware revision numbers are provided in the advisory.

Risk and Exploitability

The vulnerability received a CVSS 4.1 rating, indicating moderate impact. The EPSS score is < 1%, showing a very low but non‑zero likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to have physical access, so the likelihood of remote exploitation is low, but the potential for credential compromise remains if the device is not secured against physical tampering.

Generated by OpenCVE AI on September 15, 2026 at 15:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Retrieve and install the latest firmware or security update from Contec for the affected CPSN devices
  • Restrict physical access to the devices by placing them in lockable enclosures or controlling access with appropriate security policies
  • If, consider disabling nonessential remote access functions or replacing the unit with a version that correctly encrypts stored credentials

Generated by OpenCVE AI on September 15, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041
Contec remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
Vendors & Products Contec
Contec programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041
Contec remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Plaintext Password Storage Allows Credential Theft with Physical Access

Mon, 14 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Plaintext Password Storage in Contec CPSN Series Enables Credential Theft with Physical Access

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Plaintext Password Storage in Contec CPSN Series Enables Credential Theft with Physical Access

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Contec Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041 Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1 Remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.452Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82783

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:05.302Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:20.087

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:00Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password