First published: Wed Jun 08 2022(Updated: )
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
All of | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30308 is a vulnerability in Festo Controller CECC-X-M1 product family that allows unauthorized execution of system commands with root privileges due to improper access control command injection.
CVE-2022-30308 affects Festo Controller CECC-X-M1 firmware versions up to and including 3.8.14, as well as version 4.0.14.
CVE-2022-30308 has a severity rating of 9.8, which is considered critical.
To fix the CVE-2022-30308 vulnerability, it is recommended to update Festo Controller CECC-X-M1 firmware to a version higher than 4.0.14.
You can find more information about CVE-2022-30308 at this URL: https://cert.vde.com/en/advisories/VDE-2022-020/