9.8

CVE-2022-3270

Incomplete Documentation of remote functions in FESTO products.

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Festo ≫ Bus Module Cpx-e-ep Firmware Version -
   Festo ≫ Bus Module Cpx-e-ep Version -
Festo ≫ Bus Node Cpx-fb32 Firmware Version -
   Festo ≫ Bus Node Cpx-fb32 Version -
Festo ≫ Bus Node Cpx-fb33 Firmware Version -
   Festo ≫ Bus Node Cpx-fb33 Version -
Festo ≫ Bus Node Cpx-fb36 Firmware Version -
   Festo ≫ Bus Node Cpx-fb36 Version -
Festo ≫ Bus Node Cpx-fb37 Firmware Version -
   Festo ≫ Bus Node Cpx-fb37 Version -
Festo ≫ Bus Node Cpx-fb39 Firmware Version -
   Festo ≫ Bus Node Cpx-fb39 Version -
Festo ≫ Bus Node Cpx-fb40 Firmware Version -
   Festo ≫ Bus Node Cpx-fb40 Version -
Festo ≫ Bus Node Cpx-fb43 Firmware Version -
   Festo ≫ Bus Node Cpx-fb43 Version -
Festo ≫ Bus Node Cpx-m-fb34 Firmware Version -
   Festo ≫ Bus Node Cpx-m-fb34 Version -
Festo ≫ Bus Node Cpx-m-fb35 Firmware Version -
   Festo ≫ Bus Node Cpx-m-fb35 Version -
Festo ≫ Bus Node Cpx-m-fb44 Firmware Version -
   Festo ≫ Bus Node Cpx-m-fb44 Version -
Festo ≫ Bus Node Cpx-m-fb45 Firmware Version -
   Festo ≫ Bus Node Cpx-m-fb45 Version -
Festo ≫ Bus Node Cteu-ep Firmware Version -
   Festo ≫ Bus Node Cteu-ep Version -
Festo ≫ Bus Node Cteu-pn Firmware Version -
   Festo ≫ Bus Node Cteu-pn Version -
Festo ≫ Controller Cecc-d Firmware Version -
   Festo ≫ Controller Cecc-d Version -
Festo ≫ Controller Cecc-lk Firmware Version -
   Festo ≫ Controller Cecc-lk Version -
Festo ≫ Controller Cecc-s Firmware Version -
   Festo ≫ Controller Cecc-s Version -
Festo ≫ Controller Sbrd-q Firmware Version -
   Festo ≫ Controller Sbrd-q Version -
Festo ≫ Gateway Cpx-iot Firmware Version -
   Festo ≫ Gateway Cpx-iot Version -
Festo ≫ Vtem-s1-27 Firmware Version -
   Festo ≫ Vtem-s1-27 Version -
Festo ≫ Vtem-s1-c Firmware Version -
   Festo ≫ Vtem-s1-c Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.05% 0.599
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1059 Insufficient Technical Documentation

The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.

https://cert.vde.com/en/advisories/VDE-2022-041/
Third Party Advisory