Security Advisory

CVE-2022-30310

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-13 13:45:23
Last updated 2024-11-20 15:21:04
Assigner CERTVDE
State PUBLISHED

Description

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.