← Back

Festo

festo

9 CVEs • 206 products

Products (206)

Click to collapse
Toggle

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Codesys
FestoPilz+1 more
64750 8100 Firmware
750 8101 Firmware750 8102 Firmware+61 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local a...Show more
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.Show less
1Festo
99Bus Module Cpx E Ep Firmware
Bus Node Cpx Fb32 FirmwareBus Node Cpx Fb33 Firmware+96 more
Jun 17, 2026
Dec 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
1Festo
2Cpx Cec C1 Firmware
Cpx Cmxx Firmware
Jun 17, 2026
Sep 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.
1Festo
8Controller Cecc X M1 Mv S1 Firmware
Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 more
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with...Show more
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.Show less
1Festo
8Controller Cecc X M1 Mv S1 Firmware
Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 more
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with...Show more
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.Show less
1Festo
8Controller Cecc X M1 Mv S1 Firmware
Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 more
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system command...Show more
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.Show less
1Festo
8Controller Cecc X M1 Mv S1 Firmware
Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 more
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands...Show more
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.Show less
33s Software
FestoSoftmotion3d
4Cecx X C1 Modular Master Controller
Cecx X M1 Modular ControllerCodesys Runtime System+1 more
May 6, 2026
Apr 25, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to...Show more
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001.Show less
33s Software
FestoSoftmotion3d
4Cecx X C1 Modular Master Controller
Cecx X M1 Modular ControllerCodesys Runtime System+1 more
May 6, 2026
Apr 25, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attac...Show more
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.Show less