VYPR

Controller Cecc X M1 Firmware

by Festo

CVEs (5)

  • CVE-2022-3270CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

  • CVE-2022-30311CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…

  • CVE-2022-30310CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…

  • CVE-2022-30309CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control…

  • CVE-2022-30308CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control…