CVE-2023-3634 affects Festo's MSE6 product family and involves undocumented test mode functions that can be exploited by remote, authenticated attackers with low privileges. The vulnerability could result in complete compromise of system confidentiality, integrity, and availability. The attack requires network access and low-privilege credentials but involves minimal complexity, earning a CVSS score of 8.8 (HIGH). Exploitation remains inactive based on current indicators, with no evidence of public exploit code availability or significant community attention. The EPSS score of 0.00074 suggests this vulnerability has received limited real-world exploitation activity to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Festo | MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD | All Versions ImpactedCNA affecteddefault unaffected | |
| Festo | MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD | All Versions ImpactedCNA affecteddefault unaffected | |
| Festo | MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD | All Versions ImpactedCNA affecteddefault unaffected | |
| Festo | MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD | All Versions ImpactedCNA affecteddefault unaffected | |
| Festo | MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD | All Versions ImpactedCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.