CVE-2022-30308: FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30308?
CVE-2022-30308 is a vulnerability in Festo Controller CECC-X-M1 product family that allows unauthorized execution of system commands with root privileges due to improper access control command injection.
Which software versions of Festo Controller CECC-X-M1 are affected by CVE-2022-30308?
CVE-2022-30308 affects Festo Controller CECC-X-M1 firmware versions up to and including 3.8.14, as well as version 4.0.14.
What is the severity of CVE-2022-30308?
CVE-2022-30308 has a severity rating of 9.8, which is considered critical.
How can I fix the CVE-2022-30308 vulnerability?
To fix the CVE-2022-30308 vulnerability, it is recommended to update Festo Controller CECC-X-M1 firmware to a version higher than 4.0.14.
Where can I find more information about CVE-2022-30308?
You can find more information about CVE-2022-30308 at this URL: https://cert.vde.com/en/advisories/VDE-2022-020/