CVE-2022-30309: FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30309?
CVE-2022-30309 is a vulnerability in the Festo Controller CECC-X-M1 product family that allows unauthorized execution of system commands with root privileges.
How severe is CVE-2022-30309?
CVE-2022-30309 has a severity rating of 9.8, which is considered critical.
What is the affected software of CVE-2022-30309?
The affected software of CVE-2022-30309 includes Festo Controller CECC-X-M1 firmware versions up to 3.8.14 and version 4.0.14.
How can the CVE-2022-30309 vulnerability be exploited?
The CVE-2022-30309 vulnerability can be exploited by sending a specially crafted POST request to the "cecc-x-web-viewer-request-off" HTTP endpoint.
Is Festo Controller CECC-X-M1 vulnerable to CVE-2022-30309?
Yes, Festo Controller CECC-X-M1 firmware versions up to 3.8.14 and version 4.0.14 are vulnerable to CVE-2022-30309.