Impact
An improper neutralization of directives in dynamically evaluated code (Eval Injection) allows an attacker with authenticated access to the Contec CONPROSYS HMI System to execute arbitrary code. The flaw is identified as CWE‑95. Based on the description that arbitrary code can be executed, it is inferred that the attacker may be able to gain control over the application and potentially the underlying host system.
Affected Systems
The affected product is Contec's CONPROSYS HMI System, known as CHS. No specific version details are provided, so any installation that has not yet applied the vendor’s latest security fixes remains at risk.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity; the EPSS score of 0.00305 indicates a very low probability of exploitation in the near term, yet the risk remains significant because the flaw yields arbitrary code execution once authenticated. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires authenticated access, the practical risk depends on the strength of user credentials and the network perimeter protecting the HMI system, but the potential impact justifies urgent remediation.
OpenCVE Enrichment