Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the affected product is installed, therefore a wide range of privileges is permitted to a user of the PC where the affected product is installed. As a result, the user may be able to destroy the system and/or execute a malicious program.
Use CWE-732, Contec vendor hub and Conprosys Hmi System product page to widen CVE-2023-28399 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-28657, CVE-2023-28713 and CVE-2023-22339 for nearby disclosures in the same product family.