CVE Feed

    Dashboard / CVE / CVE-2014-0769

    CVE-2014-0769

    The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001.

    Published:Apr 25, 2014
    Last Modified:Jul 2, 2025
    EPS:Apr 25, 2014
    EPSS Score:0.00325
    CVSS Score:9.3

    Affected Products

    Vendor
    3s-software
    Product
    Codesys Runtime System
    Vendor
    Festo
    Product
    Cecx-x-c1 Modular Master Controller
    Vendor
    Festo
    Product
    Cecx-x-m1 Modular Controller
    Vendor
    Softmotion3d
    Product
    Softmotion

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High