ZeroHour

CVE-2022-30308

CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

Vendors
festo
Products
controller cecc-x-m1 firmware, controller cecc-x-m1-mv firmware, controller cecc-x-m1-mv-s1 firmware, controller cecc-x-m1-ys-l1 firmware, controller cecc-x-m1-ys-l2 firmware, controller cecc-x-m1-y-yjkp firmware, servo press kit yjkp firmware, servo press kit yjkp- firmware
Weakness
CWE-78, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.