CVE-2022-3079: Festo: CPX-CEC-C1 and CMXX, Missing Authentication for Critical Webpage Function
Published Sep 20, 2022
·Updated
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.
Affected Software
4 affected components
Festo Cpx-cmxx Firmware<=2.0.12
Festo CPX-CMXX
Festo Cpx-cec-c1 Firmware<=1.2.34
Festo CPX-CEC-C1
Event History
Sep 20, 2022
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-3079.
2
What is the severity of CVE-2022-3079?
The severity of CVE-2022-3079 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2022-3079?
The Festo control block CPX-CEC-C1 firmware versions up to and including 1.2.34 and CPX-CMXX firmware versions up to and including 2.0.12 are affected by CVE-2022-3079.
4
What is the impact of CVE-2022-3079?
CVE-2022-3079 allows unauthenticated remote access to critical webpage functions, which may cause a denial of service.
5
Where can I find more information about CVE-2022-3079?
You can find more information about CVE-2022-3079 in the VDE advisory at https://cert.vde.com/en/advisories/VDE-2022-036.