First published: Wed Jun 08 2022(Updated: )
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
All of | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30309 is a vulnerability in the Festo Controller CECC-X-M1 product family that allows unauthorized execution of system commands with root privileges.
CVE-2022-30309 has a severity rating of 9.8, which is considered critical.
The affected software of CVE-2022-30309 includes Festo Controller CECC-X-M1 firmware versions up to 3.8.14 and version 4.0.14.
The CVE-2022-30309 vulnerability can be exploited by sending a specially crafted POST request to the "cecc-x-web-viewer-request-off" HTTP endpoint.
Yes, Festo Controller CECC-X-M1 firmware versions up to 3.8.14 and version 4.0.14 are vulnerable to CVE-2022-30309.