← Vulnerability feed

Vulnerability record · CVE-2022-44456 · published 19 December 2022

CVE-2022-44456: CONPROSYS HMI System OS command injection via crafted request

Contec · Conprosys Hmi System

CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier contains an OS command injection flaw (CWE-78). A remote attacker can send a specially crafted request to execute arbitrary OS commands on the server hosting the product. The flaw is network-reachable, needs no authentication or user interaction, and carries a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-78 · OS command injection
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and high EPSS make this a critical pre-auth remote code execution risk.

What it is

CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier contains an OS command injection flaw (CWE-78). A remote attacker can send a specially crafted request to execute arbitrary OS commands on the server hosting the product. The flaw is network-reachable, needs no authentication or user interaction, and carries a critical CVSS score of 9.8.

Impact

An attacker gains arbitrary OS command execution on the CHS server, which can lead to full compromise of confidentiality, integrity and availability of that host. This may allow data theft, service disruption, or use of the server as a pivot into the industrial control environment.

Attack surface

The vulnerability is reachable over the network via a crafted request to the CHS service, as reflected by the AV:N vector. No authentication (PR:N) and no user interaction (UI:N) are required, so any host that can reach the CHS interface is a potential entry point.

Exploitation

The record does not state that exploitation has been observed; CVE-2022-44456 is not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.69877, 99.3rd percentile), indicating a strong likelihood of attempted exploitation, and vendor references include a patch advisory.

What to do

  • Apply the vendor patch from the CON-TEC advisory for CHS (patch reference in the record) and upgrade beyond Ver.3.4.4.
  • Restrict network access to the CHS server so only trusted management hosts can reach its service ports.
  • Place CHS behind a firewall or segmented network zone and avoid exposing it to untrusted networks or the internet.
  • Monitor vendor advisories and JVN VU96873821 for updated guidance and any revised fixed versions.
  • If patching is delayed, consider temporary compensating controls such as an application-layer filter or WAF rule blocking malformed requests to CHS.

Detection

  • Monitor CHS server process logs and OS audit logs for unexpected child processes or command shells spawned by the CHS service.
  • Alert on suspicious outbound connections or file writes originating from the CHS server host.
  • Review network traffic to CHS management ports for anomalous or malformed requests, especially from unexpected source addresses.
  • Correlate endpoint detection alerts for command execution (e.g., cmd.exe, /bin/sh) with the CHS service process on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-44456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-28657Contec conprosys hmi system missing authorization vulnerabilityImproper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is in…EPSS 0.71%8.1CVE-2023-28713Contec conprosys hmi system cleartext storage of sensitive data vulnerabilityPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in…EPSS 0.43%7.8CVE-2023-28399Contec conprosys hmi system incorrect permission assignment vulnerabilityIncorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not …EPSS 0.18%7.5CVE-2023-22339Contec conprosys hmi system improper access control vulnerabilityImproper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access r…EPSS 1.1%7.5CVE-2023-22331Contec conprosys hmi system improper privilege management vulnerabilityUse of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user c…EPSS 1.0%7.2CVE-2023-29154Contec conprosys hmi system sql injection vulnerabilitySQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an admi…EPSS 41%6.9CVE-2025-34081Contec conprosys hmi system vulnerabilityThe Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for…EPSS 0.64%6.5CVE-2023-22324Contec conprosys hmi system sql injection vulnerabilitySQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQ…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2022-44456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.