Vulnerability record · CVE-2022-44456 · published 19 December 2022
CVE-2022-44456: CONPROSYS HMI System OS command injection via crafted request
Contec · Conprosys Hmi System
CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier contains an OS command injection flaw (CWE-78). A remote attacker can send a specially crafted request to execute arbitrary OS commands on the server hosting the product. The flaw is network-reachable, needs no authentication or user interaction, and carries a critical CVSS score of 9.8.
Description
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and high EPSS make this a critical pre-auth remote code execution risk.
What it is
CONPROSYS HMI System (CHS) Ver.3.4.4 and earlier contains an OS command injection flaw (CWE-78). A remote attacker can send a specially crafted request to execute arbitrary OS commands on the server hosting the product. The flaw is network-reachable, needs no authentication or user interaction, and carries a critical CVSS score of 9.8.
Impact
An attacker gains arbitrary OS command execution on the CHS server, which can lead to full compromise of confidentiality, integrity and availability of that host. This may allow data theft, service disruption, or use of the server as a pivot into the industrial control environment.
Attack surface
The vulnerability is reachable over the network via a crafted request to the CHS service, as reflected by the AV:N vector. No authentication (PR:N) and no user interaction (UI:N) are required, so any host that can reach the CHS interface is a potential entry point.
Exploitation
The record does not state that exploitation has been observed; CVE-2022-44456 is not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.69877, 99.3rd percentile), indicating a strong likelihood of attempted exploitation, and vendor references include a patch advisory.
What to do
- Apply the vendor patch from the CON-TEC advisory for CHS (patch reference in the record) and upgrade beyond Ver.3.4.4.
- Restrict network access to the CHS server so only trusted management hosts can reach its service ports.
- Place CHS behind a firewall or segmented network zone and avoid exposing it to untrusted networks or the internet.
- Monitor vendor advisories and JVN VU96873821 for updated guidance and any revised fixed versions.
- If patching is delayed, consider temporary compensating controls such as an application-layer filter or WAF rule blocking malformed requests to CHS.
Detection
- Monitor CHS server process logs and OS audit logs for unexpected child processes or command shells spawned by the CHS service.
- Alert on suspicious outbound connections or file writes originating from the CHS server host.
- Review network traffic to CHS management ports for anomalous or malformed requests, especially from unexpected source addresses.
- Correlate endpoint detection alerts for command execution (e.g., cmd.exe, /bin/sh) with the CHS service process on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/vu/JVNVU96873821/index.html | Third Party AdvisoryVDB Entry |
| https://www.contec.com/api/downloadlogger?download=/-/media/Contec/jp/support/security-info/contec_security_chs_221014_e | Vendor Advisory |
| https://www.contec.com/download/contract/contract4/?itemid=ea8039aa-3434-4999-9ab6-897aa690210c&downloaditemid=866d7d3c- | PatchVendor Advisory |
| https://jvn.jp/en/vu/JVNVU96873821/index.html | Third Party AdvisoryVDB Entry |
| https://www.contec.com/api/downloadlogger?download=/-/media/Contec/jp/support/security-info/contec_security_chs_221014_e | Vendor Advisory |
| https://www.contec.com/download/contract/contract4/?itemid=ea8039aa-3434-4999-9ab6-897aa690210c&downloaditemid=866d7d3c- | PatchVendor Advisory |
Track CVE-2022-44456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-44456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.