# CVE-2022-3270

## Summary

- **CVE ID:** CVE-2022-3270
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-1059
- **Published:** Dec 1, 2022
- **Last Modified:** Mar 13, 2026

## Description

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.

## Affected Products

- Festo SE — Bus module CPX-E-EP (all)
- Festo SE — Bus node CPX-FB32 (all)
- Festo SE — Bus node CPX-FB33 (all)
- Festo SE — Bus node CPX-FB36 (all)
- Festo SE — Bus node CPX-FB37 (all)
- Festo SE — Bus node CPX-FB39 (all)
- Festo SE — Bus node CPX-FB40 (all)
- Festo SE — Bus node CPX-FB43 (all)
- Festo SE — Bus node CPX-M-FB34 (all)
- Festo SE — Bus node CPX-M-FB35 (all)
- Festo SE — Bus node CPX-M-FB44 (all)
- Festo SE — Bus node CPX-M-FB45 (all)
- Festo SE — Bus node CTEU-EP (all)
- Festo SE — Bus node CTEU-PN (all)
- Festo SE — Bus node CTEU-PN-EX1C (all)
- Festo SE — Camera system CHB-C-N (all)
- Festo SE — Compact Vision System SBO*-C-* (all)
- Festo SE — Compact Vision System SBO*-M-* (all)
- Festo SE — Compact Vision System SBO*-Q-* (all)
- Festo SE — Control block CPX-CEC (all)
- Festo SE — Control block CPX-CEC-C1 (all)
- Festo SE — Control block CPX-CEC-C1-V3 (all)
- Festo SE — Control block CPX-CEC-M1 (all)
- Festo SE — Control block CPX-CEC-M1-V3 (all)
- Festo SE — Control block CPX-CEC-S1-V3 (all)
- Festo SE — Control block CPX-CMXX (all)
- Festo SE — Control block CPX-FEC-1-IE (all)
- Festo SE — Controller CECC-D (all)
- Festo SE — Controller CECC-D-BA (all)
- Festo SE — Controller CECC-LK (all)
- Festo SE — Controller CECC-S (all)
- Festo SE — Controller CECC-X-* (all)
- Festo SE — Controller CECX-X-C1 (all)
- Festo SE — Controller CECX-X-M1 (all)
- Festo SE — Controller CMXH-ST2-C5-7-DIOP (all)
- Festo SE — Controller CPX-E-CEC-* (all)
- Festo SE — Controller SBRD-Q (all)
- Festo SE — EtherNet/IP interface CPX-AP-I-EP-M12 (all)
- Festo SE — EtherNet/IP interface CPX-AP-I-PN-M12 (all)
- Festo SE — Gateway CPX-IOT (all)
- Festo SE — Integrated drive EMCA-EC-67-* (all)
- Festo SE — Motor controller CMMO-ST-C5-1-DION (all)
- Festo SE — Motor controller CMMO-ST-C5-1-DIOP (all)
- Festo SE — Motor controller CMMO-ST-C5-1-LKP (all)
- Festo SE — Motor controller CMMP-AS-* (all)
- Festo SE — Motor controller CMMT-AS-* (all)
- Festo SE — Operator unit CDPX-X-A-S-10 (all)
- Festo SE — Operator unit CDPX-X-A-W-13 (all)
- Festo SE — Operator unit CDPX-X-A-W-4 (all)
- Festo SE — Operator unit CDPX-X-A-W-7 (all)
- Festo SE — Planar surface gantry EXCM-* (all)
- Festo SE — Servo drive CMMT-ST-C8-1C-EP-S0 (all)
- Festo SE — Servo drive CMMT-ST-C8-1C-PN-S0 (all)
- Festo SE — VTEM-S1-* (all)
- Festo SE — Bus module CPX-E-PN (all)

## References

- [CNA](https://cert.vde.com/en/advisories/VDE-2022-041/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.95%
- **EPSS Percentile:** 76.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._