Sceawere

Vulnerability Detail

CVE-2026-82778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CONPROSYS PAC Directory Listing Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
Integrated Type CPS-PC341[][]-*-9201
Attack Type
Exposure of information through directory listing
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-14T07:17:19.393Z",
  "pubdate": "2026-09-14T07:17:19.393Z",
  "executiveSummary": "The CONPROSYS PAC Series is susceptible to an information exposure vulnerability arising from an insecure directory listing configuration.\nThis vulnerability allows remote, unauthenticated attackers to browse and retrieve directory contents on the target device.\nThe flaw stems from an improper server-side configuration that fails to restrict access to directory structures.\nExploitation does not require authentication, significantly lowering the barrier for entry for malicious actors.\nSuccessful exploitation allows an attacker to map the underlying file system, identify sensitive configuration files, firmware components, or data logs stored on the device.\nExposure of this nature facilitates reconnaissance, enabling attackers to uncover secondary vulnerabilities, sensitive credentials, or internal file structures that could be leveraged for further system compromise or unauthorized data access.",
  "technicalDetails": "The vulnerability is classified as an improper restriction of directory browsing, leading to an unauthorized information disclosure of the server's file system structure.\nThe root cause is a misconfigured web server component within the CONPROSYS PAC Series that allows directory indexing to be enabled for specific Uniform Resource Locators (URLs) without requiring authentication.\nWhen a remote attacker sends a specially crafted HTTP request to a target URL representing a directory on the web root or associated application paths, the server responds with a structured list of files and subdirectories contained within that path.\nThe attack flow is straightforward: an unauthenticated user sends a GET request to the target directory URL. The web server, lacking a security constraint or an index file (e.g., index.html) to prevent automated listing, generates an HTML or machine-readable directory listing response.\nThe vulnerable component resides in the web interface framework utilized by the CONPROSYS PAC Series. Because the interface is exposed via the network to handle remote management or monitoring tasks, any actor with network reachability to the device can trigger this behavior.\nPost-exploitation, the attacker gains full visibility into the directory structure. By recursively traversing these lists, an attacker can pinpoint the location of sensitive system files, backup files, log files, and configuration scripts.\nThis reconnaissance phase is critical for the attacker, as it identifies potential entry points for secondary attacks, such as reading configuration files containing hardcoded credentials, identifying specific software versions for targeted exploitation, or locating sensitive operational data that may be processed or stored on the PAC.\nThe impact is primarily categorized as an information disclosure; however, the data gained is frequently a precursor to more severe exploits, such as remote code execution or unauthorized configuration changes, by identifying the exact paths of scripts or sensitive application resources."
}
CVE-2026-82778: CONPROSYS PAC Directory Listing Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere