Beveiligingsadvies

CVE-2022-30309

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-06-13 13:45:21
Laatst bijgewerkt 2024-09-16 22:15:41
Toegewezen door CERTVDE
CVSS-score 9.8
Status PUBLISHED

Beschrijving

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.