PT-2022-20059 · Festo · Festo Controller Cecc-X-M1

M. Illes

+1

·

Published

2022-06-13

·

Updated

2024-09-16

·

CVE-2022-30309

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Festo Controller CECC-X-M1 product family (affected versions not specified)
Description The issue concerns the http-endpoint "cecc-x-web-viewer-request-off" POST request, which does not check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-30309

Affected Products

Festo Controller Cecc-X-M1