The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote malicious users to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
softmotion3d softmotion - |
||
festo cecx-x-m1_modular_controller - |
||
3s-software codesys_runtime_system - |
||
festo cecx-x-c1_modular_master_controller - |