A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of
several Festo products, was found. This could lead to remote code execution and escalation of
privileges giving full admin access on the host system.
Update A, 2023-12-05
Affected products are vulnerable to remote code execution via command injection in the web-based management by an attacker.
There is a misconfiguration of access rights to a configuration tool of the web-based-management for a specific user, which allows to reset passwords of other users (except root). This allows an authenticated attacker to elevate his privileges.
Multiple Weidmueller products are affected by recent WIBU vulnerability.