Critical severity9.8NVD Advisory· Published Jun 13, 2022· Updated Jun 17, 2026
CVE-2022-30310
CVE-2022-30310
Description
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*range: <=3.8.14
- cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:4.0.14:*:*:*:*:*:*:*
cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*range: <=3.8.14
- cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:4.0.14:*:*:*:*:*:*:*
cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*range: <=3.8.14
- (no CPE)range: 3.0.0
- cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:*:*:*:*:*:*:*:*Range: <=3.8.14
- cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:*:*:*:*:*:*:*:*Range: <=3.8.14
cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*range: <=3.8.14
- cpe:2.3:o:festo:controller_cecc-x-m1_firmware:4.0.14:*:*:*:*:*:*:*
- cpe:2.3:o:festo:servo_press_kit_yjkp-_firmware:*:*:*:*:*:*:*:*Range: <=3.8.14
- cpe:2.3:o:festo:servo_press_kit_yjkp_firmware:*:*:*:*:*:*:*:*Range: <=3.8.14
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 4.0.14
3.0.0+ 1 more
- (no CPE)range: 3.0.0
- (no CPE)range: 4.0.14
- Range: 3.0.0
- Range: 3.0.0
Patches
Vulnerability mechanics
References
1- cert.vde.com/en/advisories/VDE-2022-020/nvdVendor Advisory
News mentions
0No linked articles in our index yet.