Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-3270

Disclosure Date: December 01, 2022 (last updated November 09, 2023)
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Attacker Value
Unknown

CVE-2022-30311

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30310

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30309

Disclosure Date: June 08, 2022 (last updated November 29, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
0
Attacker Value
Unknown

CVE-2022-30308

Disclosure Date: June 08, 2022 (last updated September 17, 2024)
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.