Back to Database
Status published
Critical
CVE-2022-3270
Incomplete Documentation of remote functions in FESTO products.
Vulnerability Description
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3270
Credits & Attribution
No credits recorded in the NVD database.
Affected Vendor
Festo SE
View all reports →Affected Software
Bus module CPX-E-EP, Bus node CPX-FB32, Bus node CPX-FB33, Bus node CPX-FB36, Bus node CPX-FB37, Bus node CPX-FB39, Bus node CPX-FB40, Bus node CPX-FB43, Bus node CPX-M-FB34, Bus node CPX-M-FB35, Bus node CPX-M-FB44, Bus node CPX-M-FB45, Bus node CTEU-EP, Bus node CTEU-PN, Bus node CTEU-PN-EX1C, Camera system CHB-C-N, Compact Vision System SBO*-C-*, Compact Vision System SBO*-M-*, Compact Vision System SBO*-Q-*, Control block CPX-CEC, Control block CPX-CEC-C1, Control block CPX-CEC-C1-V3, Control block CPX-CEC-M1, Control block CPX-CEC-M1-V3, Control block CPX-CEC-S1-V3, Control block CPX-CMXX, Control block CPX-FEC-1-IE, Controller CECC-D, Controller CECC-D-BA, Controller CECC-LK, Controller CECC-S, Controller CECC-X-*, Controller CECX-X-C1, Controller CECX-X-M1, Controller CMXH-ST2-C5-7-DIOP, Controller CPX-E-CEC-*, Controller SBRD-Q, EtherNet/IP interface CPX-AP-I-EP-M12, EtherNet/IP interface CPX-AP-I-PN-M12, Gateway CPX-IOT, Integrated drive EMCA-EC-67-*, Motor controller CMMO-ST-C5-1-DION, Motor controller CMMO-ST-C5-1-DIOP, Motor controller CMMO-ST-C5-1-LKP, Motor controller CMMP-AS-*, Motor controller CMMT-AS-*, Operator unit CDPX-X-A-S-10, Operator unit CDPX-X-A-W-13, Operator unit CDPX-X-A-W-4, Operator unit CDPX-X-A-W-7, Planar surface gantry EXCM-*, Servo drive CMMT-ST-C8-1C-EP-S0, Servo drive CMMT-ST-C8-1C-PN-S0, VTEM-S1-*, Bus module CPX-E-PN
Vulnerable Versions:
all
Timeline
Official Publish:
December 1st, 2022
Last Modified:
April 24th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.