← back
CVE-2023-3634highCWE-1242

Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
In short

Festo MSE6 devices have hidden test functions that aren't documented in the user manual. An attacker with basic access to the device remotely could exploit these functions to completely compromise the system's security, stealing data, modifying it, or shutting it down.

Technical detail

The MSE6 product family contains undocumented remote-accessible test mode functions that can be invoked by a low-privileged authenticated attacker. Exploitation requires network access to the device and valid credentials; successful exploitation results in complete compromise of confidentiality, integrity, and availability (CIA triad).

Summary generated and translated by AI from the official description.
In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, integrity and availability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H