Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2014-0760

HIGH · 9.3 CVSS Gepubliceerd: CWE-287

Beschrijving NL

De Festo CECX-X-C1 Modulaire Master Controller met CoDeSys en CECX-X-M1
Modulaire Controller met CoDeSys en SoftMotion zorgen voor een ongedocumenteerde
toegangsmethode met het FTP-protocol, waardoor een externe aanvaller willekeurige code kan uitvoeren of een denial of service kan veroorzaken (toepassing
crash) via niet-gespecificeerde vectoren.

Origineel (Engels) tonen

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
Modular Controller with CoDeSys and SoftMotion provide an undocumented
access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application
crash) via unspecified vectors.

Vendors

3s-software Festo Softmotion3d

Affected products

Codesys Runtime System Cecx-x-c1 Modular Master Controller Softmotion Cecx-x-m1 Modular Controller

References