Critical

Festo MSE6-C2M/D2M/E2M

All CISA Advisories

Overview

The Festo MSE6-C2M/D2M/E2M series has a critical vulnerability (CVE-2023-3634) that allows remote authenticated attackers to exploit undocumented test modes, leading to severe risks including loss of confidentiality, integrity, and availability. This vulnerability has a CVSS score of 8.8, indicating a high severity level and necessitating immediate attention and remediation.

Key Takeaways

  • Affected Systems: Affected products include: MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD, MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD, MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD, MSE6-C2M-5000-FB44-D-RG-BAR-AMI-AGD, MSE6-D2M-5000-CBUS-S-RG-BAR-VCB-AGD, MSE6-E2M-5000-FB13-AGD, MSE6-E2M-5000-FB36-AGD, MSE6-E2M-5000-FB37-AGD, MSE6-E2M-5000-FB43-AGD, MSE6-E2M-5000-FB44-AGD. Vendor: Festo SE & Co. KG.
  • Action Required: Festo has updated the user documentation in the next product version to address this issue.
  • Timeline: Disclosed on [date]

Original Article Summary

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Festo SE & Co. KG Equipment: MSE6-C2M/D2M/E2M Vulnerability: Hidden Functionality 2. RISK EVALUATION Successful exploitation of this vulnerability could lead to a complete loss of confidentiality, integrity, and availability. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS Festo reports the following products are affected: MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD: All versions MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD: All versions MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD: All versions MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD: All versions MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD: All versions MSE6-C2M-5000-FB44-D-RG-BAR-AMI-AGD: All versions MSE6-D2M-5000-CBUS-S-RG-BAR-VCB-AGD: All versions MSE6-E2M-5000-FB13-AGD: All versions MSE6-E2M-5000-FB36-AGD: All versions MSE6-E2M-5000-FB37-AGD: All versions MSE6-E2M-5000-FB43-AGD: All versions MSE6-E2M-5000-FB44-AGD: All versions 3.2 VULNERABILITY OVERVIEW 3.2.1 Hidden Functionality CWE-912 In Festo MSE6 product-family, a remote authenticated, low-privileged attacker could use functions of undocumented test mode, which could lead to a complete loss of confidentiality, integrity, and availability. CVE-2023-3634 has been assigned to this vulnerability. A CVSS v3.1 base score of 8.8 has been calculated; the CVSS vector string is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 3.3 BACKGROUND CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing COUNTRIES/AREAS DEPLOYED: Worldwide COMPANY HEADQUARTERS LOCATION: Germany 3.4 RESEARCHER Festo coordinated this vulnerability with CERT@VDE. 4. MITIGATIONS Festo has updated the user documentation in the next product version to address this issue. For more information, see the associated Festo SE & Co. KG security advisory FSA-202304 FSA-202304: Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions - HTML, FSA-202304: Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions - CSAF. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. 5. UPDATE HISTORY November 20, 2025: Initial Republication of Festo FSA-202304

Impact

Affected products include: MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD, MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD, MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD, MSE6-C2M-5000-FB44-D-RG-BAR-AMI-AGD, MSE6-D2M-5000-CBUS-S-RG-BAR-VCB-AGD, MSE6-E2M-5000-FB13-AGD, MSE6-E2M-5000-FB36-AGD, MSE6-E2M-5000-FB37-AGD, MSE6-E2M-5000-FB43-AGD, MSE6-E2M-5000-FB44-AGD. Vendor: Festo SE & Co. KG.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on [date]

Remediation

Festo has updated the user documentation in the next product version to address this issue. Recommended defensive measures include minimizing network exposure for control systems, using firewalls, and secure remote access methods like VPNs. Organizations should also perform impact analysis and risk assessments before deploying defensive measures.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, CVE, Exploit, and 3 more.

Related Coverage

Estée Lauder discloses data breach via Oracle E-Business flaw

BleepingComputer

Estée Lauder has informed customers about a data breach that occurred due to a vulnerability in Oracle's E-Business Suite, which the company uses for its human resources operations. Hackers exploited this flaw, potentially compromising the personal data of affected individuals. While the specific details about the type of data accessed have not been disclosed, this incident raises concerns about the security of sensitive information within large organizations. Customers are advised to monitor their accounts for any unusual activity as the company works to address the breach. This incident serves as a reminder for businesses to ensure their software systems are regularly updated and secure against known vulnerabilities.

Jul 20, 2026

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputer

A new strain of malware, named EncForge, has been developed by the JadePuffer autonomous AI agent. This malware specifically targets AI-related assets, including training datasets, vector databases, and model checkpoints, by encrypting them and holding them for ransom. This shift in focus to AI model data represents a concerning trend, as organizations increasingly rely on these assets for their operations. If attackers succeed, they can disrupt AI development and implementation, potentially causing significant financial and operational damage to affected companies. As AI technology continues to evolve, the need for robust security measures to protect these critical assets becomes ever more urgent.

Jul 20, 2026

Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack

SCM feed for Latest

Hugging Face, a company known for its work in AI and machine learning, has recently turned to an open-weight model named GLM 5.2 to investigate a cyberattack driven by AI agents. The shift to this model comes after they encountered limitations with their previous frontier model guardrails, which restricted their capabilities. This situation illustrates the evolving challenges in cybersecurity, particularly as AI technologies become more integrated into both offensive and defensive strategies. The use of AI in cyberattacks raises significant concerns about the potential for more sophisticated and automated threats. Companies in the tech sector should take note of these developments as they may need to adjust their security measures to counteract AI-driven vulnerabilities.

Jul 20, 2026

South Korea proposes new rules for seizing self-custody crypto wallets

SCM feed for Latest

South Korea is looking to change its Criminal Procedure Act to allow authorities to seize digital assets stored in self-custody wallets, like hardware wallets. This shift comes as part of broader efforts to regulate the cryptocurrency space and address potential misuse. The proposed legislation indicates a growing concern over how digital assets are managed and the need for law enforcement to access these funds during investigations. If passed, this law could impact individuals who hold cryptocurrencies independently, raising questions about privacy and the security of self-custody solutions. As the crypto landscape evolves, the implications of such regulations could significantly affect users' trust in self-custody wallets.

Jul 20, 2026

Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts

SCM feed for Latest

Ecopetrol, Colombia's largest petroleum company, recently confirmed a ransomware attempt that resulted in the theft of data from 3,300 user accounts. The breach involved an unidentified attacker gaining access to the company's IT systems and exfiltrating pseudonymous data. While the exact nature of the stolen information hasn't been disclosed, incidents like this raise significant concerns about data privacy and the potential for further exploitation of the compromised accounts. Ecopetrol's acknowledgment of the breach highlights the ongoing challenges faced by organizations in safeguarding their digital infrastructures. Users of Ecopetrol services should remain vigilant for any unusual activity related to their accounts, as the implications of such breaches can be far-reaching.

Jul 20, 2026

Head of federal AI testing lab resigns after three months

SCM feed for Latest

Chris Fall, the director of a federal AI testing lab, has resigned after just three months in the role. His departure raises questions about the stability and direction of the lab, which is crucial for overseeing the safety and efficacy of artificial intelligence technologies used by government agencies. Fall's brief tenure may indicate challenges within the lab or broader issues related to federal AI initiatives. As AI continues to evolve rapidly, the leadership and strategic focus of such organizations are vital for ensuring that AI systems are developed responsibly and securely. The implications of this leadership change could affect ongoing projects and collaborations in the federal AI landscape.

Jul 20, 2026