First published: Fri Apr 25 2014(Updated: )
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
CoDeSys runtime system | ||
FESTO cecx-x-c1 modular master controller firmware | ||
SoftMotion | ||
Festo CECX-X-M1 Modular Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0760 has been assigned a high severity level due to the potential for remote code execution and denial of service.
To fix CVE-2014-0760, it is recommended to update the firmware for the affected Festo controllers and disable FTP access if it is not needed.
CVE-2014-0760 affects the Festo CECX-X-C1 and CECX-X-M1 Modular Controllers along with CoDeSys runtime systems and SoftMotion.
Attackers can exploit CVE-2014-0760 to execute arbitrary code or cause application crashes via the undocumented FTP access method.
CVE-2014-0760 is not version-specific; it impacts all versions of CoDeSys runtime systems associated with the affected devices.