FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability
Vulnerability Description
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-30310
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo
More from Festo
View All →Affected Vendor
Festo
View all reports →