CVE-2023-3634
8.8Festo · MSE6 product-family
The Festo MSE6 product family contains an undocumented test mode that, if accessed by a low-privileged authenticated remote attacker, can lead to a total loss of system confidentiality and integrity.
Executive summary
A critical vulnerability in the Festo MSE6 product family allows authenticated, low-privileged remote attackers to trigger undocumented features, resulting in a full compromise of system security.
Vulnerability
This vulnerability involves the inclusion of undocumented features (CWE-1242) within the Festo MSE6 series firmware. A remote attacker with low-level authenticated access can activate this test mode to gain full control over the device.
Business impact
The exploitation of this vulnerability results in a complete loss of confidentiality, integrity, and availability for the affected industrial control components. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized manipulation of industrial processes, potential safety hazards, or significant operational downtime.
Remediation
Immediate Action: Review the official Festo security advisory at the CERT VDE link provided in the references to identify available firmware updates or configuration changes for your specific hardware model.
Proactive Monitoring: Monitor network traffic and system access logs for any unauthorized use of administrative or undocumented test functions by low-privileged user accounts.
Compensating Controls: Restrict network access to the management interfaces of these devices to trusted management subnets only, and enforce strong authentication policies to minimize the risk of credential compromise.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the high CVSS severity and the potential for total system compromise, organizations using the Festo MSE6 series should prioritize this issue in their maintenance cycle. Administrators must consult the vendor documentation immediately to determine if a patch is available or if specific configuration hardening is required to disable the vulnerable test mode.