Festo manufactures a broad portfolio of industrial automation controllers and motion-control systems, with its vulnerability exposure concentrating in the CECC-series embedded controllers used across manufacturing and process-automation environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around OS command injection, authorization bypass, authentication weaknesses, and privilege-management flaws that reflect the command-interface and administrative-access patterns typical of industrial control firmware. Defenders managing Festo controllers should prioritize inventory and access restrictions for these devices, particularly in networked or internet-connected deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Festo over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3270CRITICAL In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity a | Dec 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30309CRITICAL In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in | Jun 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30308CRITICAL In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in u | Jun 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30311CRITICAL In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unautho | Jun 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-30310CRITICAL In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unautho | Jun 13, 2022 | 9.8 | 29 | NO | NO |
CVE-2014-0760HIGH The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
Modular Controller with CoDeSys and SoftMotion provide an undocumented
access method involving the FTP pr | Apr 25, 2014 | 9.3 | 29 | NO | NO |
CVE-2020-12069HIGH In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing | Dec 26, 2022 | 7.8 | 26 | NO | NO |
CVE-2014-0769HIGH The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP | Apr 25, 2014 | 9.3 | 23 | NO | NO |
CVE-2022-3079HIGH Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service. | Sep 20, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Festo.
Media articles that mention a CVE ID that affects a product developed by Festo — matched by CVE ID, not by vendor name.