Vulnerabilites related to festo - controller_cecc-x-m1-ys-l1
Vulnerability from fkie_nvd
Published
2022-12-01 11:15
Modified
2024-11-21 07:19
Severity ?
Summary
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Impacted products
Vendor Product Version
festo bus_module_cpx-e-ep_firmware -
festo bus_module_cpx-e-ep -
festo bus_node_cpx-fb32_firmware -
festo bus_node_cpx-fb32 -
festo bus_node_cpx-fb33_firmware -
festo bus_node_cpx-fb33 -
festo bus_node_cpx-fb36_firmware -
festo bus_node_cpx-fb36 -
festo bus_node_cpx-fb37_firmware -
festo bus_node_cpx-fb37 -
festo bus_node_cpx-fb39_firmware -
festo bus_node_cpx-fb39 -
festo bus_node_cpx-fb40_firmware -
festo bus_node_cpx-fb40 -
festo bus_node_cpx-fb43_firmware -
festo bus_node_cpx-fb43 -
festo bus_node_cpx-m-fb34_firmware -
festo bus_node_cpx-m-fb34 -
festo bus_node_cpx-m-fb35_firmware -
festo bus_node_cpx-m-fb35 -
festo bus_node_cpx-m-fb44_firmware -
festo bus_node_cpx-m-fb44 -
festo bus_node_cpx-m-fb45_firmware -
festo bus_node_cpx-m-fb45 -
festo bus_node_cteu-ep_firmware -
festo bus_node_cteu-ep -
festo bus_node_cteu-pn_firmware -
festo bus_node_cteu-pn -
festo bus_node_cteu-pn-ex1c_firmware -
festo bus_node_cteu-pn-ex1c -
festo camera_system_chb-c-n_firmware -
festo camera_system_chb-c-n -
festo cecx-x-c1_modular_master_controller_firmware -
festo cecx-x-c1_modular_master_controller -
festo cecx-x-m1_modular_controller_firmware -
festo cecx-x-m1_modular_controller -
festo compact_vision_system_sboc-c_firmware -
festo compact_vision_system_sboc-c -
festo compact_vision_system_sboc-m_firmware -
festo compact_vision_system_sboc-m -
festo compact_vision_system_sboc-q_firmware -
festo compact_vision_system_sboc-q -
festo compact_vision_system_sboi-c_firmware -
festo compact_vision_system_sboi-c -
festo compact_vision_system_sboi-m_firmware -
festo compact_vision_system_sboi-m -
festo compact_vision_system_sboi-q_firmware -
festo compact_vision_system_sboi-q -
festo control_block_cpx-cec_firmware -
festo control_block_cpx-cec -
festo control_block_cpx-cec-c1_firmware -
festo control_block_cpx-cec-c1 -
festo control_block_cpx-cec-c1-v3_firmware -
festo control_block_cpx-cec-c1-v3 -
festo control_block_cpx-cec-m1_firmware -
festo control_block_cpx-cec-m1 -
festo control_block_cpx-cec-m1-v3_firmware -
festo control_block_cpx-cec-m1-v3 -
festo control_block_cpx-cec-s1-v3_firmware -
festo control_block_cpx-cec-s1-v3 -
festo control_block_cpx-cmxx_firmware -
festo control_block_cpx-cmxx -
festo control_block_cpx-fec-1-ie_firmware -
festo control_block_cpx-fec-1-ie -
festo controller_cecc-d_firmware -
festo controller_cecc-d -
festo controller_cecc-d-ba_firmware -
festo controller_cecc-d-ba -
festo controller_cecc-lk_firmware -
festo controller_cecc-lk -
festo controller_cecc-s_firmware -
festo controller_cecc-s -
festo controller_cecc-x-m1_firmware -
festo controller_cecc-x-m1 -
festo controller_cecc-x-m1-mv_firmware -
festo controller_cecc-x-m1-mv -
festo controller_cecc-x-m1-mv-s1_firmware -
festo controller_cecc-x-m1-mv-s1 -
festo controller_cecc-x-m1-y-yjkp_firmware -
festo controller_cecc-x-m1-y-yjkp -
festo controller_cecc-x-m1-ys-l1_firmware -
festo controller_cecc-x-m1-ys-l1 -
festo controller_cecc-x-m1-ys-l2_firmware -
festo controller_cecc-x-m1-ys-l2 -
festo controller_cmxh-st2-c5-7-diop_firmware -
festo controller_cmxh-st2-c5-7-diop -
festo controller_sbrd-q_firmware -
festo controller_sbrd-q -
festo ethernet\/ip_interface_cpx-ap-i-ep-m12_firmware -
festo ethernet\/ip_interface_cpx-ap-i-ep-m12 -
festo ethernet\/ip_interface_cpx-ap-i-pn-m12_firmware -
festo ethernet\/ip_interface_cpx-ap-i-pn-m12 -
festo gateway_cpx-iot_firmware -
festo gateway_cpx-iot -
festo integrated_drive_emca-ec-67_firmware -
festo integrated_drive_emca-ec-67 -
festo integrated_drive_emca-ec-67-m-1te-ep_firmware -
festo integrated_drive_emca-ec-67-m-1te-ep -
festo motor_controller_cmmo-st-c5-1-dion_firmware -
festo motor_controller_cmmo-st-c5-1-dion -
festo motor_controller_cmmo-st-c5-1-diop_firmware -
festo motor_controller_cmmo-st-c5-1-diop -
festo motor_controller_cmmo-st-c5-1-lkp_firmware -
festo motor_controller_cmmo-st-c5-1-lkp -
festo motor_controller_cmmp-as-c10-11a-p3-m0_firmware -
festo motor_controller_cmmp-as-c10-11a-p3-m0 -
festo motor_controller_cmmp-as-c10-11a-p3-m3_firmware -
festo motor_controller_cmmp-as-c10-11a-p3-m3 -
festo motor_controller_cmmp-as-c15-11a-p3-m3_firmware -
festo motor_controller_cmmp-as-c15-11a-p3-m3 -
festo motor_controller_cmmp-as-c2-3a-m0_firmware -
festo motor_controller_cmmp-as-c2-3a-m0 -
festo motor_controller_cmmp-as-c2-3a-m3_firmware -
festo motor_controller_cmmp-as-c2-3a-m3 -
festo motor_controller_cmmp-as-c5-11a-p3-m0_firmware -
festo motor_controller_cmmp-as-c5-11a-p3-m0 -
festo motor_controller_cmmp-as-c5-11a-p3-m3_firmware -
festo motor_controller_cmmp-as-c5-11a-p3-m3 -
festo motor_controller_cmmp-as-c5-3a-m0_firmware -
festo motor_controller_cmmp-as-c5-3a-m0 -
festo motor_controller_cmmp-as-c5-3a-m3_firmware -
festo motor_controller_cmmp-as-c5-3a-m3 -
festo operator_unit_cdpx-x-a-s-10_firmware -
festo operator_unit_cdpx-x-a-s-10 -
festo operator_unit_cdpx-x-a-w-13_firmware -
festo operator_unit_cdpx-x-a-w-13 -
festo operator_unit_cdpx-x-a-w-4_firmware -
festo operator_unit_cdpx-x-a-w-4 -
festo operator_unit_cdpx-x-a-w-7_firmware -
festo operator_unit_cdpx-x-a-w-7 -
festo planar_surface_gantry_excm-30_firmware -
festo planar_surface_gantry_excm-30 -
festo planar_surface_gantry_excm-40_firmware -
festo planar_surface_gantry_excm-40 -
festo servo_cmmt-as-c12-11a-p3-ec-s1_firmware -
festo servo_cmmt-as-c12-11a-p3-ec-s1 -
festo servo_cmmt-as-c12-11a-p3-ep-s1_firmware -
festo servo_cmmt-as-c12-11a-p3-ep-s1 -
festo servo_cmmt-as-c12-11a-p3-mp-s1_firmware -
festo servo_cmmt-as-c12-11a-p3-mp-s1 -
festo servo_cmmt-as-c12-11a-p3-pn-s1_firmware -
festo servo_cmmt-as-c12-11a-p3-pn-s1 -
festo servo_cmmt-as-c2-11a-p3-ec-s1_firmware -
festo servo_cmmt-as-c2-11a-p3-ec-s1 -
festo servo_cmmt-as-c2-11a-p3-ep-s1_firmware -
festo servo_cmmt-as-c2-11a-p3-ep-s1 -
festo servo_cmmt-as-c2-11a-p3-mp-s1_firmware -
festo servo_cmmt-as-c2-11a-p3-mp-s1 -
festo servo_cmmt-as-c2-11a-p3-pn-s1_firmware -
festo servo_cmmt-as-c2-11a-p3-pn-s1 -
festo servo_cmmt-as-c2-3a-ec-s1_firmware -
festo servo_cmmt-as-c2-3a-ec-s1 -
festo servo_cmmt-as-c2-3a-ep-s1_firmware -
festo servo_cmmt-as-c2-3a-ep-s1 -
festo servo_cmmt-as-c2-3a-mp-s1_firmware -
festo servo_cmmt-as-c2-3a-mp-s1 -
festo servo_cmmt-as-c2-3a-pn-s1_firmware -
festo servo_cmmt-as-c2-3a-pn-s1 -
festo servo_cmmt-as-c3-11a-p3-ec-s1_firmware -
festo servo_cmmt-as-c3-11a-p3-ec-s1 -
festo servo_cmmt-as-c3-11a-p3-ep-s1_firmware -
festo servo_cmmt-as-c3-11a-p3-ep-s1 -
festo servo_cmmt-as-c3-11a-p3-mp-s1_firmware -
festo servo_cmmt-as-c3-11a-p3-mp-s1 -
festo servo_cmmt-as-c3-11a-p3-pn-s1_firmware -
festo servo_cmmt-as-c3-11a-p3-pn-s1 -
festo servo_cmmt-as-c4-3a-ec-s1_firmware -
festo servo_cmmt-as-c4-3a-ec-s1 -
festo servo_cmmt-as-c4-3a-ep-s1_firmware -
festo servo_cmmt-as-c4-3a-ep-s1 -
festo servo_cmmt-as-c4-3a-mp-s1_firmware -
festo servo_cmmt-as-c4-3a-mp-s1 -
festo servo_cmmt-as-c4-3a-pn-s1_firmware -
festo servo_cmmt-as-c4-3a-pn-s1 -
festo servo_cmmt-as-c5-11a-p3-ec-s1_firmware -
festo servo_cmmt-as-c5-11a-p3-ec-s1 -
festo servo_cmmt-as-c5-11a-p3-ep-s1_firmware -
festo servo_cmmt-as-c5-11a-p3-ep-s1 -
festo servo_cmmt-as-c5-11a-p3-mp-s1_firmware -
festo servo_cmmt-as-c5-11a-p3-mp-s1 -
festo servo_cmmt-as-c5-11a-p3-pn-s1_firmware -
festo servo_cmmt-as-c5-11a-p3-pn-s1 -
festo servo_cmmt-as-c7-11a-p3-ec-s1_firmware -
festo servo_cmmt-as-c7-11a-p3-ec-s1 -
festo servo_cmmt-as-c7-11a-p3-ep-s1_firmware -
festo servo_cmmt-as-c7-11a-p3-ep-s1 -
festo servo_cmmt-as-c7-11a-p3-mp-s1_firmware -
festo servo_cmmt-as-c7-11a-p3-mp-s1 -
festo servo_cmmt-as-c7-11a-p3-pn-s1_firmware -
festo servo_cmmt-as-c7-11a-p3-pn-s1 -
festo servo_drive_cmmt-st-c8-1c-ep-s0_firmware -
festo servo_drive_cmmt-st-c8-1c-ep-s0 -
festo servo_drive_cmmt-st-c8-1c-pn-s0_firmware -
festo servo_drive_cmmt-st-c8-1c-pn-s0 -
festo vtem-s1-27_firmware -
festo vtem-s1-27 -
festo vtem-s1-c_firmware -
festo vtem-s1-c -



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_module_cpx-e-ep_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C81405AE-BB69-458B-B8FB-E4FD5A6D2796",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_module_cpx-e-ep:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DFF274A8-2685-49B1-BE9A-C22DE36578CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb32_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2403998F-0509-4D92-9DD3-09E535DAE2EE",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb32:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5E233DED-8DA3-4452-8711-49894C1B7292",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb33_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D8EA7FE3-026E-4530-820A-5E807A4618FB",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb33:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "60EA3B7D-EA95-47ED-B62C-1613D2F1354A",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb36_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F18D033D-3680-46CC-8E1E-BA5DD0064A8E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb36:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D04765FB-A6B0-47BF-B28F-8037F7D246B7",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb37_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B1D45624-D81F-4764-B079-CDB8CEE8B0A7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb37:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "744F3AE1-223D-4F12-A69C-FFF0F26A6739",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb39_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6D7E8DE4-39C2-407C-A189-D0AA206457EB",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb39:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CC4F0206-811B-4DCD-AB40-C038B93CDF86",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb40_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CBAC93B7-44B5-4386-A824-C1EF03580085",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb40:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A70C3220-FCF4-426D-8F08-5FA9E96AB9B9",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-fb43_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B968C82A-06D3-4230-AD2E-86109D4822BF",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-fb43:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "617F33B6-168C-4816-B86F-A1382B199434",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-m-fb34_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "290062C7-01FC-45FE-AEE3-9F12C9D554B7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-m-fb34:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A3CBA5-C416-446A-91FE-2885C581BE6C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-m-fb35_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C775B55C-4590-43C2-9E54-A76A870943D1",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-m-fb35:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "98810706-78D6-46BF-A955-237573CFC4A0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-m-fb44_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "4EFA8518-89C0-40C4-A714-673EBFB219F7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-m-fb44:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "281ABE3E-3BB9-4F85-8E09-D6C6F535AEF7",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cpx-m-fb45_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B22A6776-B228-4B85-829A-44A9B15978E6",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cpx-m-fb45:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2430D0F4-ED0C-4504-ABBA-D4C2BDAF65C5",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cteu-ep_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A1C5504B-966B-4EE3-9497-04686093105F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cteu-ep:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "37E67652-1FE9-4C5E-8B41-424C3FB15532",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cteu-pn_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "1687EE04-5B5C-471A-A0DD-E9AB86A23FDA",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cteu-pn:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8121D070-F972-4667-BC01-8A17C7746D60",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:bus_node_cteu-pn-ex1c_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "EBAC1A42-F16C-4BDF-AF29-809BDC4D2962",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:bus_node_cteu-pn-ex1c:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "89256A7B-C53B-4CC8-A661-18A67209996A",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:camera_system_chb-c-n_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A89FEDB8-32FC-49BB-B926-4C6B6518605A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:camera_system_chb-c-n:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B94147BE-0B1E-46B7-A5C9-7AEE972D002E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:cecx-x-c1_modular_master_controller_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "117E5C79-0834-4E4B-AE9D-A0E7B66B519F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:cecx-x-c1_modular_master_controller:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D4428AC4-B79E-4DDC-8CB1-6F91F835945B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:cecx-x-m1_modular_controller_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FFC10EDD-0553-4483-BDA6-C26A029D6F1C",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:cecx-x-m1_modular_controller:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FA6BC4C2-B93A-42A3-85A4-7161C769EE04",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboc-c_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A4674881-1AA8-44F3-94FF-984A163D90D8",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboc-c:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D1FFED06-D10B-411F-A71D-25E9ADB20A35",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboc-m_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "56CCE9F2-9FB1-4EE4-928C-71C795E24285",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboc-m:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "430DD1E0-A22D-441E-8C53-7BAC1A4B064E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboc-q_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C74CDC4C-B93D-41AE-AD07-D78C3AAED398",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboc-q:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "266D90FB-FCC2-442A-90B2-3EA2560AF8C0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboi-c_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E5F14983-8053-4F07-B785-E575D4F4EAC8",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboi-c:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FD12AFC0-AD38-455E-A22B-4FC924CC3C89",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboi-m_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3776BFA0-EA96-43B4-A104-E980D0342AFC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboi-m:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "036C6FCF-272B-4FF6-8BE1-269C58DA9618",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:compact_vision_system_sboi-q_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "1344B704-5BB7-4D11-B525-F9BF4E412CEC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:compact_vision_system_sboi-q:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "46AF2EFB-426A-469C-8ED6-393C2E66BD27",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "10E9EA00-D68E-4FD5-9C6F-D3188138C525",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5AFE2D53-C6D7-4E76-9C4B-F1C03CC7519B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec-c1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A676AF30-B30F-43DA-831A-71F4AE9611AE",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec-c1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FA48E0EB-4BBD-4666-82CE-E7AE49A29BF1",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec-c1-v3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "971A6F55-6312-44A8-ACF3-D9922DF2A30F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec-c1-v3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "18536087-0D45-4436-B047-CFBE8F7BEB07",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec-m1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AF7D1257-91DD-4D70-A06E-8E08C5072B88",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "693B3345-3AE0-48D1-B6C8-CB94751FFEDE",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec-m1-v3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A7BC4CB5-3058-4C82-9B12-913F3C751C91",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec-m1-v3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3DD700C3-F6FA-4119-9497-1AACE7113081",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cec-s1-v3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65BFD3F0-04BA-4BB8-A1EB-DB5C1BE24C76",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cec-s1-v3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "11BFD704-EDCA-4553-98C5-8FD314D5249C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-cmxx_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E0E4DFC8-8376-44CA-9ADB-C0131FD811A9",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-cmxx:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2A954DD0-DB8A-4034-B140-C6B3E0E484D2",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:control_block_cpx-fec-1-ie_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "36E7D88E-30AD-41E7-8595-ECAD75B9AD8A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:control_block_cpx-fec-1-ie:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8E3E472D-C6FB-4037-9C97-F315D4F2716F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-d_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "1DD571E4-6F9D-48DB-A503-01088C670004",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-d:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D5F17E63-45C3-48C7-916C-272FEB02E8C7",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-d-ba_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "15B5045E-E5CB-4DD8-84ED-E0F6F490B53A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-d-ba:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F349C5AA-9323-4135-B7FB-EB5014A8E684",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-lk_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8FD07C48-C3A4-4C1B-B1F5-C5ADD7767B3A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-lk:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AA82BF77-3362-46A9-8ED3-BD7A07779562",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-s_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CC9B2C47-E743-4175-AB70-3653A833F7CA",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-s:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "07DFC73D-3164-402D-A7D0-D37610206F8D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3BB9F285-8477-46D3-8787-2D56BC569A43",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A6F168-897E-4300-9C87-B987EA538473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8DE9D69E-ADA1-4820-979E-494ABB1F6AE1",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE2D43FB-F307-4F7E-8DEF-F026ACE110CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "098322ED-3900-4CE2-A6A1-31A297E86D65",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AA08A0C-ADD6-4683-90E8-21D537E1E19B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0EE5F5C-82A5-41CC-86E4-84D4D8A25B73",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-y-yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7F3C797-DE05-4FBC-A3BE-08548B746374",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "15AC954E-37C0-4C7C-89FD-52E3523343DD",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81C720A3-8847-487A-917C-E9863ABC8690",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B6E1FC42-4D69-4C61-A843-33CBE7308693",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C95A7B4C-C5BA-4C57-96A2-BB435ADE1ED8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cmxh-st2-c5-7-diop_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "52C811D2-CFC0-4743-A313-25223C280BD3",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cmxh-st2-c5-7-diop:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "11B08DF1-AA39-4938-8EA2-CE5860C15E9C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_sbrd-q_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6E4A6116-C4D2-4DB3-A6F0-67E5EF380376",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_sbrd-q:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D8B9D34A-DD99-449D-A880-3C0B121F2EF6",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:ethernet\\/ip_interface_cpx-ap-i-ep-m12_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DABB7376-0FFB-497A-A4BE-A28403D843D5",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:ethernet\\/ip_interface_cpx-ap-i-ep-m12:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "407895CE-9581-4426-88E3-723F80769DDD",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:ethernet\\/ip_interface_cpx-ap-i-pn-m12_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F9716CB9-BE17-47C5-A556-BDB5C0BD5106",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:ethernet\\/ip_interface_cpx-ap-i-pn-m12:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5DEB200C-5C4D-4933-A389-A5286711AA8D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:gateway_cpx-iot_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F05949BA-4396-4A73-AAA4-23FCD7A3E682",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:gateway_cpx-iot:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6E9B84C3-CDED-4822-9C5E-ECEDB7B0C05E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:integrated_drive_emca-ec-67_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AC309043-776C-4D3F-80C5-65CA84B4BE1E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:integrated_drive_emca-ec-67:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CF6EBF99-B80C-4BD1-AA99-3ED085B4B333",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:integrated_drive_emca-ec-67-m-1te-ep_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F332E717-06F7-4DFA-89ED-F1E523AAFFC3",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:integrated_drive_emca-ec-67-m-1te-ep:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6A08AFB6-34EB-47EC-8787-7C01A564D72C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-dion_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "61BC9F42-6959-4CB8-9953-A89B3D1DCA2B",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmo-st-c5-1-dion:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "28043558-A49D-45C2-B513-373B548A0507",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-diop_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E3C5FCD5-D550-41CD-9E4C-92198B5E79A7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmo-st-c5-1-diop:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0AECC2FE-C094-4403-B5F7-F360639005B8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-lkp_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "973D19BB-109C-450B-BFD5-7A2A14C8EDB5",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmo-st-c5-1-lkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "31DA3C07-5748-403B-B070-5F52AF475434",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c10-11a-p3-m0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "ED473D77-8403-4F24-A79A-68EA1ACE74EC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c10-11a-p3-m0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5FE6C625-AE58-433C-8FCF-D13801E0072F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c10-11a-p3-m3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "566A012D-668D-4957-AB83-49E150D2FF0F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c10-11a-p3-m3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B67F495-C59F-4C0A-A273-7A7BF0A1D354",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c15-11a-p3-m3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E473547F-A85C-4409-82F9-07ACF8290753",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c15-11a-p3-m3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "7529E9CF-3883-45F2-84BE-F8C3F5AF5FE5",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c2-3a-m0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "91C30D79-D052-4E92-B3AB-8E3C823F577A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c2-3a-m0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D1F92996-D656-48A5-9958-F06F920B5003",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c2-3a-m3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "147361CE-41EC-49DE-980E-10BE06338812",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c2-3a-m3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "70239C7E-FDFA-49EE-899D-D179D34C5948",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c5-11a-p3-m0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C2FECB1-BE1F-4183-A910-03F9095119C4",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c5-11a-p3-m0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F1869E94-27B3-4804-B4AE-62E468294A26",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c5-11a-p3-m3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DC8137AE-4FFC-4646-965A-E38D2A8E401E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c5-11a-p3-m3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D0F92AB3-8B19-427F-909E-6ADA4148BCB0",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c5-3a-m0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "7D0188A9-D36E-462D-8F2E-6442FEEE1600",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c5-3a-m0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "47EA1751-DDCE-4BB0-8E9E-5ADC747CB403",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:motor_controller_cmmp-as-c5-3a-m3_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E099AE22-C6C5-4C82-BA73-8479DB18920E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:motor_controller_cmmp-as-c5-3a-m3:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "643B2C64-37EF-4927-B1B5-5A57B18A4BDB",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:operator_unit_cdpx-x-a-s-10_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "25F5CBA6-E2A3-49B0-836F-A90C2BED223A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:operator_unit_cdpx-x-a-s-10:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "07B95AD2-217D-40AF-B4DC-61A8A13ECD47",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-13_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA43D284-D6BA-475F-8085-DE0106D22129",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:operator_unit_cdpx-x-a-w-13:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81B83E51-A783-4E0B-BE6F-AFF615969A75",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-4_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81840E86-306F-4E02-8128-CE2E36F55D78",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:operator_unit_cdpx-x-a-w-4:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2452081E-8226-49B0-9D8F-8C3431EEC3FC",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-7_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "9B8F73B9-9F22-486F-8A10-720350562A0B",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:operator_unit_cdpx-x-a-w-7:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "52199341-BD45-4273-816B-8107A3F86F85",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:planar_surface_gantry_excm-30_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E02D7871-3DAB-4D35-82E9-040758FB47A4",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:planar_surface_gantry_excm-30:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DA02FAE6-77CA-4697-A6B3-F0E4EE00AF15",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:planar_surface_gantry_excm-40_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "62047E01-979E-4892-A7EE-94CEA3E0F323",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:planar_surface_gantry_excm-40:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E7CD352C-642D-4187-833E-765F9B553E59",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0B1DF0DF-0539-4C73-BB59-0E21EDC3D11F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c12-11a-p3-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F1CC412D-1B52-4316-8BB2-78EB51D3CDB3",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "91FE61BA-301B-425D-9640-D0CF5D56170E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c12-11a-p3-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B1135F28-45D1-4746-B33E-137F688FBFAA",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "910821EB-0590-4D8D-8995-9F3C922573DF",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c12-11a-p3-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "EA16A4D4-6256-42BD-B37D-9F2792ED06E3",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8FBB6B50-3CB4-42E3-B76B-AAF8274103CC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c12-11a-p3-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "EE7F121D-79F3-44A4-AAC7-61F6E6B33130",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "44BD0F5F-452A-4BA2-8539-D78D4FBC44BE",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-11a-p3-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E532FBE8-A644-407D-BE0F-67A26960B535",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "105C3B42-EF65-4049-B38E-C1D37920FD7D",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-11a-p3-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "30168E20-DEA3-442C-9CCD-0E35766BB1BD",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "079DDBE5-4B6E-416E-AFB2-7449EA80908A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-11a-p3-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "52FEDBB1-CE8A-45D6-BA21-9817ECBDCE0F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "4FB9F0C1-B2C0-4415-9905-4B3F82E79538",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-11a-p3-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8256884A-B474-44B2-8E08-CB8B86F38583",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-3a-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0F94CCF-B233-4A87-902F-D23303A7039A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-3a-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "D7ACDE7E-EEDE-4D73-9F9E-0C93C0B33F49",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-3a-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "CEB3AC79-9AD3-4C06-B240-E9FDCA80F600",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-3a-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B7CD69BD-2240-46AD-9488-296DD1D3695F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-3a-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "05FA2661-9E10-4AEB-B9E9-C0F4E95344DC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-3a-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "68C9ECDE-260C-4415-9D17-2D2B90CDDB59",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c2-3a-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E949DD74-F4F5-42F2-98DB-9EE8E80B3505",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c2-3a-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8EAAAEA4-90A8-471C-A9B1-7D1FC3C9C506",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c3-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0B3008D6-7C95-4076-A884-06B6F501CC13",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c3-11a-p3-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C5F02B62-358D-489A-AF86-84DFDDA15A75",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c3-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "681B5D3D-EDDE-4BF8-95AC-101B38135F41",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c3-11a-p3-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FC5EA729-C5F3-4B01-846A-B46244E0CC38",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c3-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "BB190CE3-0FC6-4335-A027-ED54245CE64F",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c3-11a-p3-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "AEFCAFD6-5B3B-45DB-B212-CE39AC3C541B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c3-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F4443CE8-43A6-4CAB-A684-C816CB05A3F5",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c3-11a-p3-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "9C9F58F6-2744-424B-952A-665508B4EA7E",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c4-3a-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A18AEC12-4D50-47ED-B20B-FA288D6BA6A0",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c4-3a-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0A1BF916-87D7-4C9F-92A1-DC5315C0DF3C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c4-3a-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "F4C09FFA-FB1D-43D7-8BF0-CF3BE411404A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c4-3a-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "42AF99C8-B610-4667-BA08-BA5DB0349A01",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c4-3a-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "032B12D0-E337-4FF4-960D-EF3303DA57DF",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c4-3a-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DCE0D967-E702-4B95-BF17-2A55EA3BED44",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c4-3a-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF473E74-74DD-4BC0-8AE5-C196A3CDD78A",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c4-3a-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E7564E64-E522-4014-9266-33DA4D1534E4",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c5-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6F8B7012-9213-44FE-8237-91D861C3722B",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c5-11a-p3-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "7352BB52-4A43-451D-92C4-94754E91942B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c5-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "49723D59-92C2-4CB5-9D7F-1203B4323AF3",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c5-11a-p3-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6600364D-CEE2-44A4-801C-F0668C7296FF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c5-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C4720143-E96F-4AF3-8877-A5E944A39619",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c5-11a-p3-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B5016342-06E1-4819-85D8-1DCA430A8778",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c5-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "33691A43-B333-4A11-97B7-A7ACA3AAA7DA",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c5-11a-p3-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DCBC5CA7-673A-4225-8507-48EAE13B9E2F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c7-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "2BBAF91A-BCF2-432D-B886-5EAE54963A61",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c7-11a-p3-ec-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A81DCE2D-C0BF-40AB-91D0-5C1BEC458D11",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c7-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A8248E03-B912-499C-86BA-B3B818933823",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c7-11a-p3-ep-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E556DDEE-2933-4471-B2BF-B893D932F2FE",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c7-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0EC83CC-5F63-4E67-8C88-B39C85BA1969",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c7-11a-p3-mp-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "74C7E171-A2C3-4C7F-B485-B67E067FE82B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_cmmt-as-c7-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0023C11B-3FEF-4793-9CD7-E8F86689B407",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_cmmt-as-c7-11a-p3-pn-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "45F3FE98-221D-457A-BB0D-17702EE0B750",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_drive_cmmt-st-c8-1c-ep-s0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B5D2F3CD-1B98-4A2B-99EF-C91B3D8920E5",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_drive_cmmt-st-c8-1c-ep-s0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "E47DC691-B42E-4214-9AB0-95EDC6E3456F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_drive_cmmt-st-c8-1c-pn-s0_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6379F856-328B-4FFC-8A6A-5D7C6F14C937",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_drive_cmmt-st-c8-1c-pn-s0:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "B2CC19B1-C011-4265-A64B-19A8B15D6EE3",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:vtem-s1-27_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "3FA8ADA1-185C-4CBD-9C59-2C813A72567C",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:vtem-s1-27:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "0DCB74B5-E271-4AA9-8574-98B565AB1EDB",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:vtem-s1-c_firmware:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6BAB2D87-5DF6-44DB-9DB8-CA68CAF67FBB",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:vtem-s1-c:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "148C0D69-D727-459A-B786-CDD6B9285B6C",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "In multiple products by Festo a remote unauthenticated attacker could use functions of an\u00a0undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.\n"
    },
    {
      "lang": "es",
      "value": "En muchos productos de Festo, un atacante remoto no autenticado podr\u00eda utilizar funciones de un protocolo no documentado, lo que podr\u00eda provocar una p\u00e9rdida total de confidencialidad, integridad y disponibilidad."
    }
  ],
  "id": "CVE-2022-3270",
  "lastModified": "2024-11-21T07:19:11.063",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Primary"
      }
    ]
  },
  "published": "2022-12-01T11:15:10.640",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-1059"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Secondary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}

Vulnerability from fkie_nvd
Published
2022-06-13 14:15
Modified
2024-11-21 07:02
Severity ?
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F146DE3D-9970-4732-9ECC-7562902BD228",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2DB1CA3-3E7A-4643-9654-CA5CB83FEF32",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A6F168-897E-4300-9C87-B987EA538473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "C3E5C5DE-4CB0-4C9D-BCFD-BCC45BF46038",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD5E3B15-B678-4B06-B6CC-03A5216A21C7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE2D43FB-F307-4F7E-8DEF-F026ACE110CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EC667C12-0861-4B84-B728-0F200644FCE2",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "4121C15B-B880-468E-B9F0-7C8073AB3411",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AA08A0C-ADD6-4683-90E8-21D537E1E19B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "390BAAB8-93B3-40DE-B198-EA203A61DB39",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81C720A3-8847-487A-917C-E9863ABC8690",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0611087-C956-4F88-8238-AAE3F9AA12DC",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C95A7B4C-C5BA-4C57-96A2-BB435ADE1ED8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "ECC3B011-E51F-4E33-84AD-7D85899D20BA",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-y-yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7F3C797-DE05-4FBC-A3BE-08548B746374",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8A787347-8CA6-4A3F-88FE-7086C0BDE2D3",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8D75AC25-3E04-49B0-B727-060933EC006D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp-_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "54931207-EBF7-4E8D-B480-48FA17AE94B0",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp-:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A390CCD1-9EAD-4021-9816-D4508B72467F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-off\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
    },
    {
      "lang": "es",
      "value": "En la familia de productos CECC-X-M1 de Festo en varias versiones, la petici\u00f3n POST del endpoint http \"cecc-x-web-viewer-request-off\" no comprueba la sintaxis del puerto. Esto puede resultar en una ejecuci\u00f3n no autorizada de comandos del sistema con privilegios de root debido a una inyecci\u00f3n de comandos de control de acceso inapropiados"
    }
  ],
  "id": "CVE-2022-30309",
  "lastModified": "2024-11-21T07:02:32.870",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Secondary"
      }
    ]
  },
  "published": "2022-06-13T14:15:09.163",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Primary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Secondary"
    }
  ]
}

Vulnerability from fkie_nvd
Published
2022-06-13 14:15
Modified
2024-11-21 07:02
Severity ?
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F146DE3D-9970-4732-9ECC-7562902BD228",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2DB1CA3-3E7A-4643-9654-CA5CB83FEF32",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A6F168-897E-4300-9C87-B987EA538473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "C3E5C5DE-4CB0-4C9D-BCFD-BCC45BF46038",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD5E3B15-B678-4B06-B6CC-03A5216A21C7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE2D43FB-F307-4F7E-8DEF-F026ACE110CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EC667C12-0861-4B84-B728-0F200644FCE2",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "4121C15B-B880-468E-B9F0-7C8073AB3411",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AA08A0C-ADD6-4683-90E8-21D537E1E19B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "390BAAB8-93B3-40DE-B198-EA203A61DB39",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81C720A3-8847-487A-917C-E9863ABC8690",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0611087-C956-4F88-8238-AAE3F9AA12DC",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C95A7B4C-C5BA-4C57-96A2-BB435ADE1ED8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "ECC3B011-E51F-4E33-84AD-7D85899D20BA",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-y-yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7F3C797-DE05-4FBC-A3BE-08548B746374",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8A787347-8CA6-4A3F-88FE-7086C0BDE2D3",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8D75AC25-3E04-49B0-B727-060933EC006D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp-_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "54931207-EBF7-4E8D-B480-48FA17AE94B0",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp-:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A390CCD1-9EAD-4021-9816-D4508B72467F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-refresh-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
    },
    {
      "lang": "es",
      "value": "En la familia de productos CECC-X-M1 de Festo en varias versiones, la petici\u00f3n POST del endpoint http \"cecc-x-refresh-request\" no comprueba la sintaxis del puerto. Esto puede resultar en una ejecuci\u00f3n no autorizada de comandos del sistema con privilegios de root debido a una inyecci\u00f3n de comandos de control de acceso inapropiados"
    }
  ],
  "id": "CVE-2022-30311",
  "lastModified": "2024-11-21T07:02:33.180",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Secondary"
      }
    ]
  },
  "published": "2022-06-13T14:15:09.300",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Primary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Secondary"
    }
  ]
}

Vulnerability from fkie_nvd
Published
2022-06-13 14:15
Modified
2024-11-21 07:02
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F146DE3D-9970-4732-9ECC-7562902BD228",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2DB1CA3-3E7A-4643-9654-CA5CB83FEF32",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A6F168-897E-4300-9C87-B987EA538473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "C3E5C5DE-4CB0-4C9D-BCFD-BCC45BF46038",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD5E3B15-B678-4B06-B6CC-03A5216A21C7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE2D43FB-F307-4F7E-8DEF-F026ACE110CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EC667C12-0861-4B84-B728-0F200644FCE2",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "4121C15B-B880-468E-B9F0-7C8073AB3411",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AA08A0C-ADD6-4683-90E8-21D537E1E19B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "390BAAB8-93B3-40DE-B198-EA203A61DB39",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81C720A3-8847-487A-917C-E9863ABC8690",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0611087-C956-4F88-8238-AAE3F9AA12DC",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C95A7B4C-C5BA-4C57-96A2-BB435ADE1ED8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "ECC3B011-E51F-4E33-84AD-7D85899D20BA",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-y-yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7F3C797-DE05-4FBC-A3BE-08548B746374",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8A787347-8CA6-4A3F-88FE-7086C0BDE2D3",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8D75AC25-3E04-49B0-B727-060933EC006D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp-_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "54931207-EBF7-4E8D-B480-48FA17AE94B0",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp-:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A390CCD1-9EAD-4021-9816-D4508B72467F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-acknerr-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
    },
    {
      "lang": "es",
      "value": "En la familia de productos CECC-X-M1 de Festo en varias versiones, la petici\u00f3n POST del endpoint http \"cecc-x-acknerr-request\" no comprueba la sintaxis del puerto. Esto puede resultar en una ejecuci\u00f3n no autorizada de comandos del sistema con privilegios de root debido a una inyecci\u00f3n de comandos de control de acceso inapropiados"
    }
  ],
  "id": "CVE-2022-30310",
  "lastModified": "2024-11-21T07:02:33.033",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Secondary"
      },
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Secondary"
      }
    ]
  },
  "published": "2022-06-13T14:15:09.227",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Primary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Secondary"
    }
  ]
}

Vulnerability from fkie_nvd
Published
2022-06-13 14:15
Modified
2024-11-21 07:02
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "F146DE3D-9970-4732-9ECC-7562902BD228",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2DB1CA3-3E7A-4643-9654-CA5CB83FEF32",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "65A6F168-897E-4300-9C87-B987EA538473",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "C3E5C5DE-4CB0-4C9D-BCFD-BCC45BF46038",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD5E3B15-B678-4B06-B6CC-03A5216A21C7",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE2D43FB-F307-4F7E-8DEF-F026ACE110CF",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "EC667C12-0861-4B84-B728-0F200644FCE2",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "4121C15B-B880-468E-B9F0-7C8073AB3411",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-mv-s1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AA08A0C-ADD6-4683-90E8-21D537E1E19B",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "390BAAB8-93B3-40DE-B198-EA203A61DB39",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l1:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "81C720A3-8847-487A-917C-E9863ABC8690",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0611087-C956-4F88-8238-AAE3F9AA12DC",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-ys-l2:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C95A7B4C-C5BA-4C57-96A2-BB435ADE1ED8",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "ECC3B011-E51F-4E33-84AD-7D85899D20BA",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:controller_cecc-x-m1-y-yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7F3C797-DE05-4FBC-A3BE-08548B746374",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "8A787347-8CA6-4A3F-88FE-7086C0BDE2D3",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "8D75AC25-3E04-49B0-B727-060933EC006D",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:festo:servo_press_kit_yjkp-_firmware:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "54931207-EBF7-4E8D-B480-48FA17AE94B0",
              "versionEndIncluding": "3.8.14",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:festo:servo_press_kit_yjkp-:-:*:*:*:*:*:*:*",
              "matchCriteriaId": "A390CCD1-9EAD-4021-9816-D4508B72467F",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-on\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
    },
    {
      "lang": "es",
      "value": "En la familia de productos CECC-X-M1 de Festo en varias versiones, la petici\u00f3n POST del endpoint http \"cecc-x-web-viewer-request-on\" no comprueba la sintaxis del puerto. Esto puede resultar en la ejecuci\u00f3n no autorizada de comandos del sistema con privilegios de root debido a una inyecci\u00f3n de comandos de control de acceso inapropiados"
    }
  ],
  "id": "CVE-2022-30308",
  "lastModified": "2024-11-21T07:02:32.717",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "info@cert.vde.com",
        "type": "Secondary"
      },
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "published": "2022-06-13T14:15:09.097",
  "references": [
    {
      "source": "info@cert.vde.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com",
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "info@cert.vde.com",
      "type": "Primary"
    },
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Secondary"
    }
  ]
}

CVE-2022-30311 (GCVE-0-2022-30311)
Vulnerability from cvelistv5
Published
2022-06-13 13:45
Modified
2024-09-16 23:41
Severity ?
CWE
  • CWE-863 - Incorrect Authorization
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
References
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T06:48:35.703Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (4407603)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (8124922)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (4407605)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (8124923)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (4407606)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (8124924)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L1 (8082793)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L2 (8082794)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-Y-YJKP (4803891)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP (8077950)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP- (8058596)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
        }
      ],
      "datePublic": "2022-06-07T22:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIn Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \u0026quot;cecc-x-refresh-request\u0026quot; POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.\u003c/p\u003e"
            }
          ],
          "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-refresh-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863 Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-08-10T07:36:02.588Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-020",
        "discovery": "EXTERNAL"
      },
      "title": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "info@cert.vde.com",
          "DATE_PUBLIC": "2022-06-08T08:00:00.000Z",
          "ID": "CVE-2022-30311",
          "STATE": "PUBLIC",
          "TITLE": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Controller CECC-X-M1 (4407603)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1 (8124922)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (4407605)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (8124923)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (4407606)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (8124924)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L1 (8082793)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L2 (8082794)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-Y-YJKP (4803891)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP (8077950)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP- (8058596)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Festo"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-refresh-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-863 Incorrect Authorization"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://cert.vde.com/en/advisories/VDE-2022-020/",
              "refsource": "CONFIRM",
              "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
            }
          ]
        },
        "source": {
          "advisory": "VDE-2022-020",
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-30311",
    "datePublished": "2022-06-13T13:45:24.763817Z",
    "dateReserved": "2022-05-06T00:00:00",
    "dateUpdated": "2024-09-16T23:41:46.855Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-30308 (GCVE-0-2022-30308)
Vulnerability from cvelistv5
Published
2022-06-13 13:45
Modified
2024-09-16 22:40
Severity ?
CWE
  • CWE-863 - Incorrect Authorization
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
References
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T06:48:35.581Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (4407603)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (8124922)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (4407605)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (8124923)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (4407606)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (8124924)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L1 (8082793)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L2 (8082794)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-Y-YJKP (4803891)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP (8077950)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP- (8058596)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
        }
      ],
      "datePublic": "2022-06-07T22:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIn Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \u0026quot;cecc-x-web-viewer-request-on\u0026quot; POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.\u003c/p\u003e"
            }
          ],
          "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-on\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863 Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-08-10T07:34:11.747Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-020",
        "discovery": "EXTERNAL"
      },
      "title": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "info@cert.vde.com",
          "DATE_PUBLIC": "2022-06-08T08:00:00.000Z",
          "ID": "CVE-2022-30308",
          "STATE": "PUBLIC",
          "TITLE": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Controller CECC-X-M1 (4407603)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1 (8124922)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (4407605)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (8124923)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (4407606)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (8124924)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L1 (8082793)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L2 (8082794)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-Y-YJKP (4803891)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP (8077950)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP- (8058596)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Festo"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-on\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-863 Incorrect Authorization"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://cert.vde.com/en/advisories/VDE-2022-020/",
              "refsource": "CONFIRM",
              "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
            }
          ]
        },
        "source": {
          "advisory": "VDE-2022-020",
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-30308",
    "datePublished": "2022-06-13T13:45:20.015729Z",
    "dateReserved": "2022-05-06T00:00:00",
    "dateUpdated": "2024-09-16T22:40:02.831Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-30309 (GCVE-0-2022-30309)
Vulnerability from cvelistv5
Published
2022-06-13 13:45
Modified
2024-09-16 22:15
Severity ?
CWE
  • CWE-863 - Incorrect Authorization
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
References
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T06:48:35.392Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (4407603)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (8124922)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (4407605)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (8124923)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (4407606)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (8124924)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L1 (8082793)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L2 (8082794)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-Y-YJKP (4803891)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP (8077950)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP- (8058596)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
        }
      ],
      "datePublic": "2022-06-07T22:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIn Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \u0026quot;cecc-x-web-viewer-request-off\u0026quot; POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.\u003c/p\u003e"
            }
          ],
          "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-off\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863 Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-08-10T07:35:06.910Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-020",
        "discovery": "EXTERNAL"
      },
      "title": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "info@cert.vde.com",
          "DATE_PUBLIC": "2022-06-08T08:00:00.000Z",
          "ID": "CVE-2022-30309",
          "STATE": "PUBLIC",
          "TITLE": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Controller CECC-X-M1 (4407603)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1 (8124922)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (4407605)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (8124923)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (4407606)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (8124924)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L1 (8082793)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L2 (8082794)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-Y-YJKP (4803891)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP (8077950)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP- (8058596)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Festo"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-web-viewer-request-off\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-863 Incorrect Authorization"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://cert.vde.com/en/advisories/VDE-2022-020/",
              "refsource": "CONFIRM",
              "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
            }
          ]
        },
        "source": {
          "advisory": "VDE-2022-020",
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-30309",
    "datePublished": "2022-06-13T13:45:21.634733Z",
    "dateReserved": "2022-05-06T00:00:00",
    "dateUpdated": "2024-09-16T22:15:41.158Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-3270 (GCVE-0-2022-3270)
Vulnerability from cvelistv5
Published
2022-12-01 10:27
Modified
2025-04-24 20:05
Severity ?
CWE
Summary
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Impacted products
Vendor Product Version
Festo SE Bus module CPX-E-EP Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB32 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB33 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB36 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB37 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB39 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB40 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB43 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB34 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB35 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB44 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB45 Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-EP Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-PN Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-PN-EX1C Version: all
Create a notification for this product.
   Festo SE Camera system CHB-C-N Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-C-* Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-M-* Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-Q-* Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-C1 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-C1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-M1 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-M1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-S1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CMXX Version: all
Create a notification for this product.
   Festo SE Control block CPX-CMXX Version: all
Create a notification for this product.
   Festo SE Control block CPX-FEC-1-IE Version: all
Create a notification for this product.
   Festo SE Controller CECC-D Version: all
Create a notification for this product.
   Festo SE Controller CECC-D-BA Version: all
Create a notification for this product.
   Festo SE Controller CECC-LK Version: all
Create a notification for this product.
   Festo SE Controller CECC-S Version: all
Create a notification for this product.
   Festo SE Controller CECC-X-* Version: all
Create a notification for this product.
   Festo SE Controller CECX-X-C1 Version: all
Create a notification for this product.
   Festo SE Controller CECX-X-M1 Version: all
Create a notification for this product.
   Festo SE Controller CMXH-ST2-C5-7-DIOP Version: all
Create a notification for this product.
   Festo SE Controller CPX-E-CEC-* Version: all
Create a notification for this product.
   Festo SE Controller SBRD-Q Version: all
Create a notification for this product.
   Festo SE EtherNet/IP interface CPX-AP-I-EP-M12 Version: all
Create a notification for this product.
   Festo SE EtherNet/IP interface CPX-AP-I-PN-M12 Version: all
Create a notification for this product.
   Festo SE Gateway CPX-IOT Version: all
Create a notification for this product.
   Festo SE Integrated drive EMCA-EC-67-* Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-DION Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-DIOP Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-LKP Version: all
Create a notification for this product.
   Festo SE Motor controller CMMP-AS-* Version: all
Create a notification for this product.
   Festo SE Motor controller CMMT-AS-* Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-S-10 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-13 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-4 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-7 Version: all
Create a notification for this product.
   Festo SE Planar surface gantry EXCM-* Version: all
Create a notification for this product.
   Festo SE Servo drive CMMT-ST-C8-1C-EP-S0 Version: all
Create a notification for this product.
   Festo SE Servo drive CMMT-ST-C8-1C-PN-S0 Version: all
Create a notification for this product.
   Festo SE VTEM-S1-* Version: all
Create a notification for this product.
   Festo SE Bus module CPX-E-PN Version: all
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T01:07:06.476Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-3270",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-24T20:05:18.903206Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-24T20:05:32.864Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Bus module CPX-E-EP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB32",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB33",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB36",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB37",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB39",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB40",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB43",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB34",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB35",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB44",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB45",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-EP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-PN",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-PN-EX1C",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Camera system CHB-C-N",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-C-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-M-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-Q-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-C1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-C1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-M1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-M1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-S1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CMXX",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CMXX",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-FEC-1-IE",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-D",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-D-BA",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-LK",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-S",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-X-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECX-X-C1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECX-X-M1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CMXH-ST2-C5-7-DIOP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CPX-E-CEC-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller SBRD-Q",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "EtherNet/IP interface CPX-AP-I-EP-M12",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "EtherNet/IP interface CPX-AP-I-PN-M12",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Gateway CPX-IOT",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Integrated drive EMCA-EC-67-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-DION",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-DIOP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-LKP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMP-AS-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMT-AS-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-S-10",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-13",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-4",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-7",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Planar surface gantry EXCM-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Servo drive CMMT-ST-C8-1C-EP-S0",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Servo drive CMMT-ST-C8-1C-PN-S0",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "VTEM-S1-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus module CPX-E-PN",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        }
      ],
      "datePublic": "2022-11-29T12:02:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "In multiple products by Festo a remote unauthenticated attacker could use functions of an\u0026nbsp;undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.\u003cbr\u003e"
            }
          ],
          "value": "In multiple products by Festo a remote unauthenticated attacker could use functions of an\u00a0undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.\n"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-166",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-166 Force the System to Reset Values"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1059",
              "description": "CWE-1059  Incomplete Documentation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-12-13T09:12:44.661Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-041",
        "defect": [
          "CERT@VDE#64162"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "Incomplete Documentation of remote functions in FESTO products.",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-3270",
    "datePublished": "2022-12-01T10:27:52.434Z",
    "dateReserved": "2022-09-22T08:52:13.296Z",
    "dateUpdated": "2025-04-24T20:05:32.864Z",
    "requesterUserId": "a1e5283b-8f0d-401e-98b2-bc6219c0e8d1",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-30310 (GCVE-0-2022-30310)
Vulnerability from cvelistv5
Published
2022-06-13 13:45
Modified
2024-11-20 15:21
Severity ?
CWE
  • CWE-863 - Incorrect Authorization
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
References
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T06:48:35.696Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-30310",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-02-16T16:41:19.148257Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-20T15:21:04.526Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (4407603)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1 (8124922)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (4407605)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV (8124923)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (4407606)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-MV-S1 (8124924)",
          "vendor": "Festo",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.14"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L1 (8082793)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-YS-L2 (8082794)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Controller CECC-X-M1-Y-YJKP (4803891)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP (8077950)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Servo Press Kit YJKP- (8058596)",
          "vendor": "Festo",
          "versions": [
            {
              "lessThanOrEqual": "3.8.14",
              "status": "affected",
              "version": "3.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
        }
      ],
      "datePublic": "2022-06-07T22:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIn Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \u0026quot;cecc-x-acknerr-request\u0026quot; POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.\u003c/p\u003e"
            }
          ],
          "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-acknerr-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863 Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-08-10T07:35:23.988Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-020",
        "discovery": "EXTERNAL"
      },
      "title": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "info@cert.vde.com",
          "DATE_PUBLIC": "2022-06-08T08:00:00.000Z",
          "ID": "CVE-2022-30310",
          "STATE": "PUBLIC",
          "TITLE": "FESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerability"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Controller CECC-X-M1 (4407603)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1 (8124922)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (4407605)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV (8124923)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (4407606)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-MV-S1 (8124924)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "4.0.14",
                            "version_value": "4.0.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L1 (8082793)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-YS-L2 (8082794)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Controller CECC-X-M1-Y-YJKP (4803891)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP (8077950)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Servo Press Kit YJKP- (8058596)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_name": "3.0.0",
                            "version_value": "3.8.14"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Festo"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Q. Kaiser, M. Illes from ONEKEY Research Labs for reported to Festo"
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint \"cecc-x-acknerr-request\" POST request doesn\u2019t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-863 Incorrect Authorization"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://cert.vde.com/en/advisories/VDE-2022-020/",
              "refsource": "CONFIRM",
              "url": "https://cert.vde.com/en/advisories/VDE-2022-020/"
            }
          ]
        },
        "source": {
          "advisory": "VDE-2022-020",
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-30310",
    "datePublished": "2022-06-13T13:45:23.105104Z",
    "dateReserved": "2022-05-06T00:00:00",
    "dateUpdated": "2024-11-20T15:21:04.526Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}