CVE-2014-0769: Festo CECX-X-(C1/M1) Controller Improper Authentication
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0769?
CVE-2014-0769 is rated as a high severity vulnerability due to its potential for remote exploitation without authentication.
How do I fix CVE-2014-0769?
To fix CVE-2014-0769, you should ensure that proper authentication is enforced on the affected TCP ports and restrict access to the debug service.
Which systems are affected by CVE-2014-0769?
CVE-2014-0769 affects the Festo CECX-X-C1 and CECX-X-M1 Modular Controllers and the CoDeSys runtime system.
What kind of attacks can occur due to CVE-2014-0769?
CVE-2014-0769 allows remote attackers to modify configurations and possibly disrupt operations by exploiting unauthenticated access to services.
When was CVE-2014-0769 disclosed?
CVE-2014-0769 was disclosed in 2014 and has been noted for its impact on industrial control systems.