CVE-2022-30310
EUVD-2022-5270513.06.2022, 14:15
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| festo | controller_cecc-x-m1_firmware | 𝑥 ≤ 3.8.14 |
| festo | controller_cecc-x-m1_firmware | 4.0.14 |
| festo | controller_cecc-x-m1-mv_firmware | 𝑥 ≤ 3.8.14 |
| festo | controller_cecc-x-m1-mv_firmware | 4.0.14 |
| festo | controller_cecc-x-m1-mv-s1_firmware | 𝑥 ≤ 3.8.14 |
| festo | controller_cecc-x-m1-mv-s1_firmware | 4.0.14 |
| festo | controller_cecc-x-m1-ys-l1_firmware | 𝑥 ≤ 3.8.14 |
| festo | controller_cecc-x-m1-ys-l2_firmware | 𝑥 ≤ 3.8.14 |
| festo | controller_cecc-x-m1-y-yjkp_firmware | 𝑥 ≤ 3.8.14 |
| festo | servo_press_kit_yjkp_firmware | 𝑥 ≤ 3.8.14 |
| festo | servo_press_kit_yjkp-_firmware | 𝑥 ≤ 3.8.14 |
𝑥
= Vulnerable software versions