CVE-2023-3634
Received
Received - Intake
Undocumented Test Mode Allows Remote Authenticated Privilege Escalation in Festo MSE
Publication date: 2026-04-16
Last updated on: 2026-04-16
Assigner: CERT VDE
Description
Description
In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, integrity and availability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| festo | mse6 | * |
| festo | mse6-c2m | * |
| festo | mse6-d2m | * |
| festo | mse6-e2m | * |
| festo | mse6-c2m-5000 | * |
| festo | mse6-d2m-5000 | * |
| festo | mse6-e2m-5000 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1242 | The device includes chicken bits or undocumented features that can create entry points for unauthorized actors. |