CVE-2022-3270 | Incomplete Documentation of remote functions in FESTO products.

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

Published: 2022-12-01 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2022-3270 is rated High Risk (66/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.96%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2022-3270

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-15 0.73% 0.96% +0.23%
2 2025-12-10 0.32% 0.73% +0.41%
3 2025-12-02 0.32%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2022-3270

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]

Weakness enumeration for CVE-2022-3270

Affected software / configurations for CVE-2022-3270

Vendor Product Version Raw CPE
festo bus_module_cpx-e-ep_firmware cpe:2.3:o:festo:bus_module_cpx-e-ep_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb32_firmware cpe:2.3:o:festo:bus_node_cpx-fb32_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb33_firmware cpe:2.3:o:festo:bus_node_cpx-fb33_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb36_firmware cpe:2.3:o:festo:bus_node_cpx-fb36_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb37_firmware cpe:2.3:o:festo:bus_node_cpx-fb37_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb39_firmware cpe:2.3:o:festo:bus_node_cpx-fb39_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb40_firmware cpe:2.3:o:festo:bus_node_cpx-fb40_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-fb43_firmware cpe:2.3:o:festo:bus_node_cpx-fb43_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-m-fb34_firmware cpe:2.3:o:festo:bus_node_cpx-m-fb34_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-m-fb35_firmware cpe:2.3:o:festo:bus_node_cpx-m-fb35_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-m-fb44_firmware cpe:2.3:o:festo:bus_node_cpx-m-fb44_firmware:-:*:*:*:*:*:*:*
festo bus_node_cpx-m-fb45_firmware cpe:2.3:o:festo:bus_node_cpx-m-fb45_firmware:-:*:*:*:*:*:*:*
festo bus_node_cteu-ep_firmware cpe:2.3:o:festo:bus_node_cteu-ep_firmware:-:*:*:*:*:*:*:*
festo bus_node_cteu-pn_firmware cpe:2.3:o:festo:bus_node_cteu-pn_firmware:-:*:*:*:*:*:*:*
festo bus_node_cteu-pn-ex1c_firmware cpe:2.3:o:festo:bus_node_cteu-pn-ex1c_firmware:-:*:*:*:*:*:*:*
festo camera_system_chb-c-n_firmware cpe:2.3:o:festo:camera_system_chb-c-n_firmware:-:*:*:*:*:*:*:*
festo cecx-x-c1_modular_master_controller_firmware cpe:2.3:o:festo:cecx-x-c1_modular_master_controller_firmware:-:*:*:*:*:*:*:*
festo cecx-x-m1_modular_controller_firmware cpe:2.3:o:festo:cecx-x-m1_modular_controller_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboc-c_firmware cpe:2.3:o:festo:compact_vision_system_sboc-c_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboc-m_firmware cpe:2.3:o:festo:compact_vision_system_sboc-m_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboc-q_firmware cpe:2.3:o:festo:compact_vision_system_sboc-q_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboi-c_firmware cpe:2.3:o:festo:compact_vision_system_sboi-c_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboi-m_firmware cpe:2.3:o:festo:compact_vision_system_sboi-m_firmware:-:*:*:*:*:*:*:*
festo compact_vision_system_sboi-q_firmware cpe:2.3:o:festo:compact_vision_system_sboi-q_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec_firmware cpe:2.3:o:festo:control_block_cpx-cec_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec-c1_firmware cpe:2.3:o:festo:control_block_cpx-cec-c1_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec-c1-v3_firmware cpe:2.3:o:festo:control_block_cpx-cec-c1-v3_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec-m1_firmware cpe:2.3:o:festo:control_block_cpx-cec-m1_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec-m1-v3_firmware cpe:2.3:o:festo:control_block_cpx-cec-m1-v3_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cec-s1-v3_firmware cpe:2.3:o:festo:control_block_cpx-cec-s1-v3_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-cmxx_firmware cpe:2.3:o:festo:control_block_cpx-cmxx_firmware:-:*:*:*:*:*:*:*
festo control_block_cpx-fec-1-ie_firmware cpe:2.3:o:festo:control_block_cpx-fec-1-ie_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-d_firmware cpe:2.3:o:festo:controller_cecc-d_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-d-ba_firmware cpe:2.3:o:festo:controller_cecc-d-ba_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-lk_firmware cpe:2.3:o:festo:controller_cecc-lk_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-s_firmware cpe:2.3:o:festo:controller_cecc-s_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1_firmware cpe:2.3:o:festo:controller_cecc-x-m1_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1-mv_firmware cpe:2.3:o:festo:controller_cecc-x-m1-mv_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1-mv-s1_firmware cpe:2.3:o:festo:controller_cecc-x-m1-mv-s1_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1-y-yjkp_firmware cpe:2.3:o:festo:controller_cecc-x-m1-y-yjkp_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1-ys-l1_firmware cpe:2.3:o:festo:controller_cecc-x-m1-ys-l1_firmware:-:*:*:*:*:*:*:*
festo controller_cecc-x-m1-ys-l2_firmware cpe:2.3:o:festo:controller_cecc-x-m1-ys-l2_firmware:-:*:*:*:*:*:*:*
festo controller_cmxh-st2-c5-7-diop_firmware cpe:2.3:o:festo:controller_cmxh-st2-c5-7-diop_firmware:-:*:*:*:*:*:*:*
festo controller_sbrd-q_firmware cpe:2.3:o:festo:controller_sbrd-q_firmware:-:*:*:*:*:*:*:*
festo ethernet\/ip_interface_cpx-ap-i-ep-m12_firmware cpe:2.3:o:festo:ethernet\/ip_interface_cpx-ap-i-ep-m12_firmware:-:*:*:*:*:*:*:*
festo ethernet\/ip_interface_cpx-ap-i-pn-m12_firmware cpe:2.3:o:festo:ethernet\/ip_interface_cpx-ap-i-pn-m12_firmware:-:*:*:*:*:*:*:*
festo gateway_cpx-iot_firmware cpe:2.3:o:festo:gateway_cpx-iot_firmware:-:*:*:*:*:*:*:*
festo integrated_drive_emca-ec-67_firmware cpe:2.3:o:festo:integrated_drive_emca-ec-67_firmware:-:*:*:*:*:*:*:*
festo integrated_drive_emca-ec-67-m-1te-ep_firmware cpe:2.3:o:festo:integrated_drive_emca-ec-67-m-1te-ep_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmo-st-c5-1-dion_firmware cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-dion_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmo-st-c5-1-diop_firmware cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-diop_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmo-st-c5-1-lkp_firmware cpe:2.3:o:festo:motor_controller_cmmo-st-c5-1-lkp_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c10-11a-p3-m0_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c10-11a-p3-m0_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c10-11a-p3-m3_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c10-11a-p3-m3_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c15-11a-p3-m3_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c15-11a-p3-m3_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c2-3a-m0_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c2-3a-m0_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c2-3a-m3_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c2-3a-m3_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c5-11a-p3-m0_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c5-11a-p3-m0_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c5-11a-p3-m3_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c5-11a-p3-m3_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c5-3a-m0_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c5-3a-m0_firmware:-:*:*:*:*:*:*:*
festo motor_controller_cmmp-as-c5-3a-m3_firmware cpe:2.3:o:festo:motor_controller_cmmp-as-c5-3a-m3_firmware:-:*:*:*:*:*:*:*
festo operator_unit_cdpx-x-a-s-10_firmware cpe:2.3:o:festo:operator_unit_cdpx-x-a-s-10_firmware:-:*:*:*:*:*:*:*
festo operator_unit_cdpx-x-a-w-13_firmware cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-13_firmware:-:*:*:*:*:*:*:*
festo operator_unit_cdpx-x-a-w-4_firmware cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-4_firmware:-:*:*:*:*:*:*:*
festo operator_unit_cdpx-x-a-w-7_firmware cpe:2.3:o:festo:operator_unit_cdpx-x-a-w-7_firmware:-:*:*:*:*:*:*:*
festo planar_surface_gantry_excm-30_firmware cpe:2.3:o:festo:planar_surface_gantry_excm-30_firmware:-:*:*:*:*:*:*:*
festo planar_surface_gantry_excm-40_firmware cpe:2.3:o:festo:planar_surface_gantry_excm-40_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c12-11a-p3-ec-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c12-11a-p3-ep-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c12-11a-p3-mp-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c12-11a-p3-pn-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c12-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-11a-p3-ec-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-11a-p3-ep-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-ep-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-11a-p3-mp-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-mp-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-11a-p3-pn-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-11a-p3-pn-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-3a-ec-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-3a-ec-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-3a-ep-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-3a-ep-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-3a-mp-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-3a-mp-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c2-3a-pn-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c2-3a-pn-s1_firmware:-:*:*:*:*:*:*:*
festo servo_cmmt-as-c3-11a-p3-ec-s1_firmware cpe:2.3:o:festo:servo_cmmt-as-c3-11a-p3-ec-s1_firmware:-:*:*:*:*:*:*:*

References for CVE-2022-3270

URL Tags
https://cert.vde.com/en/advisories/VDE-2022-041/ Third Party Advisory
cvelogic Threat Intelligence