PT-2022-20061 · Festo · Festo Controller Cecc-X-M1

M. Illes

+1

·

Published

2022-06-13

·

Updated

2024-09-16

·

CVE-2022-30310

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Festo Controller CECC-X-M1 product family (affected versions not specified)
Description The issue is related to the http-endpoint "cecc-x-acknerr-request" POST request, which does not check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-30310

Affected Products

Festo Controller Cecc-X-M1