Article No° | Product Name | Affected Version(s) |
---|---|---|
4407603 | Controller CECC-X-M1 | <= 3.8.14 |
8124922 | Controller CECC-X-M1 | = 4.0.14 |
4407605 | Controller CECC-X-M1-MV | <= 3.8.14 |
8124923 | Controller CECC-X-M1-MV | = 4.0.14 |
4407606 | Controller CECC-X-M1-MV-S1 | <= 3.8.14 |
8124924 | Controller CECC-X-M1-MV-S1 | = 4.0.14 |
8082793 | Controller CECC-X-M1-YS-L1 | <= 3.8.14 |
8082794 | Controller CECC-X-M1-YS-L2 | <= 3.8.14 |
4803891 | Controller CECC-X-M1-Y-YJKP | <= 3.8.14 |
8077950 | Servo Press Kit YJKP | <= 3.8.14 |
8058596 | Servo Press Kit YJKP- | <= 3.8.14 |
The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.
Any person who is able to gain access to the webserver would be able to run arbitrary system commands on the device with root privileges.
General recommendation
Currently, Festo has not identified any specific workarounds for this vulnerability. As part of a security strategy, Festo recommends the following general defense measures to reduce the risk of exploits:
Festo strongly recommends to minimize and protect network access to connected devices with state of the art techniques and processes. For a secure operation follow the recommendations in the product manuals.
Remediation
Please update to firmware versions as described below:
Product | Product Details | Fixed in version |
Controller CECC-X-M1 | Festo:Partnumber:4407603 Festo:Ordercode:CECC-X-M1 |
>= 3.8.18 |
Controller CECC-X-M1 | Festo:Partnumber:8124922 Festo:Ordercode:CECC-X-M1 |
>= 4.0.18 |
Controller CECC-X-M1-MV | Festo:Partnumber:4407605 Festo:Ordercode:CECC-X-M1- MV |
>= 3.8.18 |
Controller CECC-X-M1-MV | Festo:Partnumber:8124923 Festo:Ordercode:CECC-X-M1- MV |
>= 4.0.18 |
Controller CECC-X-M1-MVS1 | Festo:Partnumber:4407606 Festo:Ordercode:CECC-X-M1- MV-S1 |
>= 3.8.18 |
Controller CECC-X-M1-MVS1 | Festo:Partnumber:8124924 Festo:Ordercode:CECC-X-M1- MV-S1 |
>= 4.0.18 |
Controller CECC-X-M1-YYJKP | Festo:Partnumber:4803891 Festo:Ordercode:CECC-X-M1-YYJKP |
>= 3.8.18 |
Controller CECC-X-M1-YSL1 | Festo:Partnumber:8082793 Festo:Ordercode:CECC-X-M1- YS-L1 |
>= 3.8.18 |
Controller CECC-X-M1-YSL2 | Festo:Partnumber:8082794 Festo:Ordercode:CECC-X-M1- YS-L2 |
>= 3.8.18 |
Servo Press Kit YJKP | Festo:Partnumber:8077950 Festo:Ordercode:YJKP |
>= 3.8.18 |
Servo Press Kit YJKP- | Festo:Partnumber:8058596 Festo:Ordercode:YJKP |
>= 3.8.18 |
Festo SE & Co. KG thanks the following parties for their efforts: