Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30308


In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.


Published

2022-06-13T14:15:09.097

Last Modified

2024-11-21T07:02:32.717

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78
    CWE-863
  • Type: Secondary
    CWE-78
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System festo controller_cecc-x-m1_firmware ≤ 3.8.14 Yes
Operating System festo controller_cecc-x-m1_firmware 4.0.14 Yes
Hardware festo controller_cecc-x-m1 - No
Operating System festo controller_cecc-x-m1-mv_firmware ≤ 3.8.14 Yes
Operating System festo controller_cecc-x-m1-mv_firmware 4.0.14 Yes
Hardware festo controller_cecc-x-m1-mv - No
Operating System festo controller_cecc-x-m1-mv-s1_firmware ≤ 3.8.14 Yes
Operating System festo controller_cecc-x-m1-mv-s1_firmware 4.0.14 Yes
Hardware festo controller_cecc-x-m1-mv-s1 - No
Operating System festo controller_cecc-x-m1-ys-l1_firmware ≤ 3.8.14 Yes
Hardware festo controller_cecc-x-m1-ys-l1 - No
Operating System festo controller_cecc-x-m1-ys-l2_firmware ≤ 3.8.14 Yes
Hardware festo controller_cecc-x-m1-ys-l2 - No
Operating System festo controller_cecc-x-m1-y-yjkp_firmware ≤ 3.8.14 Yes
Hardware festo controller_cecc-x-m1-y-yjkp - No
Operating System festo servo_press_kit_yjkp_firmware ≤ 3.8.14 Yes
Hardware festo servo_press_kit_yjkp - No
Operating System festo servo_press_kit_yjkp-_firmware ≤ 3.8.14 Yes
Hardware festo servo_press_kit_yjkp- - No

References