CVE-2022-3270
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.95%
- CWE
- CWE-1059
- Published
- 2022-12-01
- Last modified
- 2026-03-13
Affected products
- Festo SE Bus module CPX-E-EP
- Festo SE Bus node CPX-FB32
- Festo SE Bus node CPX-FB33
- Festo SE Bus node CPX-FB36
- Festo SE Bus node CPX-FB37
- Festo SE Bus node CPX-FB39
- Festo SE Bus node CPX-FB40
- Festo SE Bus node CPX-FB43
Weakness type
Related vulnerabilities
- CVE-2026-48035 — Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened
- CVE-2026-59084 — Apache Tomcat: EncryptInterceptor requirements not clearly documented