PatchSiren

Festo CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Festo CVE published 2022-07-06

CVE-2022-30309

CVE-2022-30309 is a critical command-injection issue in Festo Controller CECC-X-M1 family products. The affected HTTP endpoint, "cecc-x-web-viewer-request-off", does not check port syntax in a POST request, which can allow unauthorized execution of system commands with root privileges. CISA’s CSAF advisory lists multiple affected controller and servo press kit firmware builds and provides fixed versions f [truncated]

HIGH Festo CVE published 2021-09-22

CVE-2021-27500

CVE-2021-27500 is a denial-of-service issue in affected Festo devices using the EIPStackGroup OpENer EtherNet/IP stack. According to the CISA CSAF advisory, a specifically crafted packet can disrupt versions prior to 2021-02-10. The advisory covers multiple Festo SBRD-Q, SBOC-Q, and SBOI-Q product variants and states that no fix is planned, so mitigation depends on reducing exposure and disabling EtherNet [truncated]