Description
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52259 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-020/ |
|
History
Mon, 16 Sep 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. |
Subscriptions
Festo
Subscribe
Controller Cecc-x-m1
Subscribe
Controller Cecc-x-m1-mv
Subscribe
Controller Cecc-x-m1-mv-s1
Subscribe
Controller Cecc-x-m1-mv-s1 Firmware
Subscribe
Controller Cecc-x-m1-mv Firmware
Subscribe
Controller Cecc-x-m1-y-yjkp
Subscribe
Controller Cecc-x-m1-y-yjkp Firmware
Subscribe
Controller Cecc-x-m1-ys-l1
Subscribe
Controller Cecc-x-m1-ys-l1 Firmware
Subscribe
Controller Cecc-x-m1-ys-l2
Subscribe
Controller Cecc-x-m1-ys-l2 Firmware
Subscribe
Controller Cecc-x-m1 Firmware
Subscribe
Servo Press Kit Yjkp
Subscribe
Servo Press Kit Yjkp-
Subscribe
Servo Press Kit Yjkp- Firmware
Subscribe
Servo Press Kit Yjkp Firmware
Subscribe
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-16T22:40:02.831Z
Reserved: 2022-05-06T00:00:00.000Z
Link: CVE-2022-30308
No data.
Status : Modified
Published: 2022-06-13T14:15:09.097
Modified: 2024-11-21T07:02:32.717
Link: CVE-2022-30308
No data.
OpenCVE Enrichment
No data.
EUVD