CVE-2022-30311: FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability
Published Jun 13, 2022
·Updated
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Affected Software
38 affected components
Festo Controller Cecc-x-m1 Firmware<=3.8.14
Festo Controller Cecc-x-m1 Firmware=4.0.14
Festo Controller CECC-X-M1
Festo Controller Cecc-x-m1-mv Firmware<=3.8.14
Festo Controller Cecc-x-m1-mv Firmware=4.0.14
Festo Controller Cecc-x-m1-mv
Festo Controller Cecc-x-m1-mv-s1 Firmware<=3.8.14
Festo Controller Cecc-x-m1-mv-s1 Firmware=4.0.14
Festo Controller Cecc-x-m1-mv-s1
Festo Controller Cecc-x-m1-ys-l1 Firmware<=3.8.14
Festo Controller Cecc-x-m1-ys-l1
Festo Controller Cecc-x-m1-ys-l2 Firmware<=3.8.14
Festo Controller Cecc-x-m1-ys-l2
Festo Controller Cecc-x-m1-y-yjkp Firmware<=3.8.14
Festo Controller Cecc-x-m1-y-yjkp
Festo Servo Press Kit Yjkp Firmware<=3.8.14
Festo Servo Press Kit YJKP
Festo Servo Press Kit Yjkp- Firmware<=3.8.14
Festo Servo Press Kit Yjkp-
All of the following
Any of the following
Festo Controller Cecc-x-m1 Firmware<=3.8.14
Festo Controller Cecc-x-m1 Firmware=4.0.14
Festo Controller CECC-X-M1
All of the following
Any of the following
Festo Controller Cecc-x-m1-mv Firmware<=3.8.14
Festo Controller Cecc-x-m1-mv Firmware=4.0.14
Festo Controller Cecc-x-m1-mv
All of the following
Any of the following
Festo Controller Cecc-x-m1-mv-s1 Firmware<=3.8.14
Festo Controller Cecc-x-m1-mv-s1 Firmware=4.0.14
Festo Controller Cecc-x-m1-mv-s1
All of the following
Festo Controller Cecc-x-m1-ys-l1 Firmware<=3.8.14
Festo Controller Cecc-x-m1-ys-l1
All of the following
Festo Controller Cecc-x-m1-ys-l2 Firmware<=3.8.14
Festo Controller Cecc-x-m1-ys-l2
All of the following
Festo Controller Cecc-x-m1-y-yjkp Firmware<=3.8.14
Festo Controller Cecc-x-m1-y-yjkp
All of the following
Festo Servo Press Kit Yjkp Firmware<=3.8.14
Festo Servo Press Kit YJKP
All of the following
Festo Servo Press Kit Yjkp- Firmware<=3.8.14
Festo Servo Press Kit Yjkp-
Event History
Jun 13, 2022
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-30311.
2
What is the severity of CVE-2022-30311?
The severity of CVE-2022-30311 is critical.
3
Which product family is affected by CVE-2022-30311?
The Festo Controller CECC-X-M1 product family in multiple versions is affected by CVE-2022-30311.
4
What is the risk of CVE-2022-30311?
CVE-2022-30311 poses a risk of unauthorized execution of system commands with root privileges due to improper access control command injection.
5
How can I fix CVE-2022-30311?
To fix CVE-2022-30311, it is recommended to apply the latest firmware update provided by Festo.