The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
CVSS Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C3s Software Codesys Runtime System
APP3S-Softwareall versionsFesto Cecx X C1 Modular Master Controller
HWFestoall versionsFesto Cecx X M1 Modular Controller
HWFestoall versionsSoftmotion3d Softmotion
APPSoftmotion3Dall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoSAuth Bypass
Related vulnerabilities
CVE-2022-3270CRITICAL9.8PL ✓same product
Festo CPX: nieudokumentowany protokół umożliwia pełne przejęcie urządzenia
CVE-2018-5440CRITICAL9.8PL ✓same product
Stack-based Buffer Overflow w CODESYS Web Server — możliwe RCE
CVE-2012-6068CRITICAL9.8PL ✓same product
Brak uwierzytelnienia w CODESYS Runtime System umożliwia zdalne wykonanie poleceń
CVE-2012-6069CRITICAL10.0PL ✓same product
Path Traversal w CoDeSys Runtime Toolkit — nieograniczony dostęp do plików
CVE-2014-0769HIGH9.3same product
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and S...