First published: Wed Jun 08 2022(Updated: )
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
FESTO Controller CECC-X-M1 firmware | <=3.8.14 | |
FESTO Controller CECC-X-M1 firmware | =4.0.14 | |
Festo CECX-X-M1 Modular Controller | ||
All of | ||
Any of | ||
FESTO Controller cecc-x-m1-mv | <=3.8.14 | |
FESTO Controller cecc-x-m1-mv | =4.0.14 | |
FESTO Controller cecc-x-m1-mv firmware | ||
All of | ||
Any of | ||
FESTO Controller cecc-x-m1-mv-s1 | <=3.8.14 | |
FESTO Controller cecc-x-m1-mv-s1 | =4.0.14 | |
FESTO Controller cecc-x-m1-mv-s1 firmware | ||
All of | ||
FESTO Controller cecc-x-m1-ys-l1 | <=3.8.14 | |
FESTO Controller cecc-x-m1-ys-l1 firmware | ||
All of | ||
FESTO Controller cecc-x-m1-ys-l2 firmware | <=3.8.14 | |
FESTO Controller cecc-x-m1-ys-l2 firmware | ||
All of | ||
FESTO Controller cecc-x-m1-y-yjkp | <=3.8.14 | |
FESTO Controller cecc-x-m1-y-yjkp firmware | ||
All of | ||
FESTO Servo Press Kit YJKP | <=3.8.14 | |
FESTO Servo Press Kit YJKP firmware | ||
All of | ||
FESTO Servo Press Kit YJKP | <=3.8.14 | |
FESTO Servo Press Kit YJKP | ||
FESTO Controller CECC-X-M1 firmware | <=3.8.14 | |
FESTO Controller CECC-X-M1 firmware | =4.0.14 | |
Festo CECX-X-M1 Modular Controller | ||
FESTO Controller cecc-x-m1-mv | <=3.8.14 | |
FESTO Controller cecc-x-m1-mv | =4.0.14 | |
FESTO Controller cecc-x-m1-mv firmware | ||
FESTO Controller cecc-x-m1-mv-s1 | <=3.8.14 | |
FESTO Controller cecc-x-m1-mv-s1 | =4.0.14 | |
FESTO Controller cecc-x-m1-mv-s1 firmware | ||
FESTO Controller cecc-x-m1-ys-l1 | <=3.8.14 | |
FESTO Controller cecc-x-m1-ys-l1 firmware | ||
FESTO Controller cecc-x-m1-ys-l2 firmware | <=3.8.14 | |
FESTO Controller cecc-x-m1-ys-l2 firmware | ||
FESTO Controller cecc-x-m1-y-yjkp | <=3.8.14 | |
FESTO Controller cecc-x-m1-y-yjkp firmware | ||
FESTO Servo Press Kit YJKP | <=3.8.14 | |
FESTO Servo Press Kit YJKP firmware | ||
FESTO Servo Press Kit YJKP | <=3.8.14 | |
FESTO Servo Press Kit YJKP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-30311.
The severity of CVE-2022-30311 is critical.
The Festo Controller CECC-X-M1 product family in multiple versions is affected by CVE-2022-30311.
CVE-2022-30311 poses a risk of unauthorized execution of system commands with root privileges due to improper access control command injection.
To fix CVE-2022-30311, it is recommended to apply the latest firmware update provided by Festo.