First published: Mon Jun 13 2022(Updated: )
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Credit: info@cert.vde.com info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1 Firmware | =4.0.14 | |
Festo Controller CECC-X-M1 | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv | ||
All of | ||
Any of | ||
Festo Controller Cecc-x-m1-mv-s1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-mv-s1 Firmware | =4.0.14 | |
Festo Controller Cecc-x-m1-mv-s1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l1 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l1 | ||
All of | ||
Festo Controller Cecc-x-m1-ys-l2 Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-ys-l2 | ||
All of | ||
Festo Controller Cecc-x-m1-y-yjkp Firmware | <=3.8.14 | |
Festo Controller Cecc-x-m1-y-yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp | ||
All of | ||
Festo Servo Press Kit Yjkp- Firmware | <=3.8.14 | |
Festo Servo Press Kit Yjkp- |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30310 is a vulnerability in the Festo Controller CECC-X-M1 product family that allows unauthorized execution of system commands with root privileges.
CVE-2022-30310 has a severity rating of 9.8, which is considered critical.
The affected software for CVE-2022-30310 includes Festo Controller CECC-X-M1 firmware versions up to and including 3.8.14 and Festo Controller CECC-X-M1 firmware version 4.0.14.
CVE-2022-30310 exploits the vulnerability by not checking for proper port syntax in the "cecc-x-acknerr-request" POST request, allowing unauthorized execution of system commands.
No, Festo Controller CECC-X-M1-MV and Festo Controller CECC-X-M1-MV-S1 are not vulnerable to CVE-2022-30310.