CWE-1059

Insufficient Technical Documentation

The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.

CVE-2022-3270 (GCVE-0-2022-3270)
Vulnerability from cvelistv5
Published
2022-12-01 10:27
Modified
2025-04-24 20:05
Severity ?
CWE
Summary
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Impacted products
Vendor Product Version
Festo SE Bus module CPX-E-EP Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB32 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB33 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB36 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB37 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB39 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB40 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-FB43 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB34 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB35 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB44 Version: all
Create a notification for this product.
   Festo SE Bus node CPX-M-FB45 Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-EP Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-PN Version: all
Create a notification for this product.
   Festo SE Bus node CTEU-PN-EX1C Version: all
Create a notification for this product.
   Festo SE Camera system CHB-C-N Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-C-* Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-M-* Version: all
Create a notification for this product.
   Festo SE Compact Vision System SBO*-Q-* Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-C1 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-C1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-M1 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-M1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CEC-S1-V3 Version: all
Create a notification for this product.
   Festo SE Control block CPX-CMXX Version: all
Create a notification for this product.
   Festo SE Control block CPX-CMXX Version: all
Create a notification for this product.
   Festo SE Control block CPX-FEC-1-IE Version: all
Create a notification for this product.
   Festo SE Controller CECC-D Version: all
Create a notification for this product.
   Festo SE Controller CECC-D-BA Version: all
Create a notification for this product.
   Festo SE Controller CECC-LK Version: all
Create a notification for this product.
   Festo SE Controller CECC-S Version: all
Create a notification for this product.
   Festo SE Controller CECC-X-* Version: all
Create a notification for this product.
   Festo SE Controller CECX-X-C1 Version: all
Create a notification for this product.
   Festo SE Controller CECX-X-M1 Version: all
Create a notification for this product.
   Festo SE Controller CMXH-ST2-C5-7-DIOP Version: all
Create a notification for this product.
   Festo SE Controller CPX-E-CEC-* Version: all
Create a notification for this product.
   Festo SE Controller SBRD-Q Version: all
Create a notification for this product.
   Festo SE EtherNet/IP interface CPX-AP-I-EP-M12 Version: all
Create a notification for this product.
   Festo SE EtherNet/IP interface CPX-AP-I-PN-M12 Version: all
Create a notification for this product.
   Festo SE Gateway CPX-IOT Version: all
Create a notification for this product.
   Festo SE Integrated drive EMCA-EC-67-* Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-DION Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-DIOP Version: all
Create a notification for this product.
   Festo SE Motor controller CMMO-ST-C5-1-LKP Version: all
Create a notification for this product.
   Festo SE Motor controller CMMP-AS-* Version: all
Create a notification for this product.
   Festo SE Motor controller CMMT-AS-* Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-S-10 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-13 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-4 Version: all
Create a notification for this product.
   Festo SE Operator unit CDPX-X-A-W-7 Version: all
Create a notification for this product.
   Festo SE Planar surface gantry EXCM-* Version: all
Create a notification for this product.
   Festo SE Servo drive CMMT-ST-C8-1C-EP-S0 Version: all
Create a notification for this product.
   Festo SE Servo drive CMMT-ST-C8-1C-PN-S0 Version: all
Create a notification for this product.
   Festo SE VTEM-S1-* Version: all
Create a notification for this product.
   Festo SE Bus module CPX-E-PN Version: all
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T01:07:06.476Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-3270",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-24T20:05:18.903206Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-24T20:05:32.864Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Bus module CPX-E-EP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB32",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB33",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB36",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB37",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB39",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB40",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-FB43",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB34",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB35",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB44",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CPX-M-FB45",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-EP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-PN",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus node CTEU-PN-EX1C",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Camera system CHB-C-N",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-C-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-M-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Compact Vision System SBO*-Q-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-C1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-C1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-M1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-M1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CEC-S1-V3",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CMXX",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-CMXX",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Control block CPX-FEC-1-IE",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-D",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-D-BA",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-LK",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-S",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECC-X-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECX-X-C1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CECX-X-M1",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CMXH-ST2-C5-7-DIOP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller CPX-E-CEC-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Controller SBRD-Q",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "EtherNet/IP interface CPX-AP-I-EP-M12",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "EtherNet/IP interface CPX-AP-I-PN-M12",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Gateway CPX-IOT",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Integrated drive EMCA-EC-67-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-DION",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-DIOP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMO-ST-C5-1-LKP",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMP-AS-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Motor controller CMMT-AS-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-S-10",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-13",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-4",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Operator unit CDPX-X-A-W-7",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Planar surface gantry EXCM-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Servo drive CMMT-ST-C8-1C-EP-S0",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Servo drive CMMT-ST-C8-1C-PN-S0",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "VTEM-S1-*",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Bus module CPX-E-PN",
          "vendor": "Festo SE",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        }
      ],
      "datePublic": "2022-11-29T12:02:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "In multiple products by Festo a remote unauthenticated attacker could use functions of an\u0026nbsp;undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.\u003cbr\u003e"
            }
          ],
          "value": "In multiple products by Festo a remote unauthenticated attacker could use functions of an\u00a0undocumented  protocol which could lead to a complete loss of confidentiality, integrity and availability.\n"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-166",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-166 Force the System to Reset Values"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1059",
              "description": "CWE-1059  Incomplete Documentation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-12-13T09:12:44.661Z",
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE"
      },
      "references": [
        {
          "url": "https://cert.vde.com/en/advisories/VDE-2022-041/"
        }
      ],
      "source": {
        "advisory": "VDE-2022-041",
        "defect": [
          "CERT@VDE#64162"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "Incomplete Documentation of remote functions in FESTO products.",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "cveId": "CVE-2022-3270",
    "datePublished": "2022-12-01T10:27:52.434Z",
    "dateReserved": "2022-09-22T08:52:13.296Z",
    "dateUpdated": "2025-04-24T20:05:32.864Z",
    "requesterUserId": "a1e5283b-8f0d-401e-98b2-bc6219c0e8d1",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2026-48035 (GCVE-0-2026-48035)
Vulnerability from cvelistv5
Published
2026-07-24 18:43
Modified
2026-07-27 20:23
CWE
  • CWE-1059 - Insufficient Technical Documentation
Summary
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
Impacted products
Vendor Product Version
kerberosmansour hulumi Version: < 1.4.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-48035",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-27T17:26:10.575563Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-27T20:23:56.410Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "hulumi",
          "vendor": "kerberosmansour",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 1.4.0"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal \u2014 while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1059",
              "description": "CWE-1059: Insufficient Technical Documentation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-24T18:43:35.696Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73"
        },
        {
          "name": "https://github.com/kerberosmansour/hulumi/pull/178",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/kerberosmansour/hulumi/pull/178"
        },
        {
          "name": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0"
        }
      ],
      "source": {
        "advisory": "GHSA-2mxr-p26x-mj73",
        "discovery": "UNKNOWN"
      },
      "title": "Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-48035",
    "datePublished": "2026-07-24T18:43:35.696Z",
    "dateReserved": "2026-05-20T18:15:53.577Z",
    "dateUpdated": "2026-07-27T20:23:56.410Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-59084 (GCVE-0-2026-59084)
Vulnerability from cvelistv5
Published
2026-07-14 08:24
Modified
2026-07-14 13:51
Severity ?
CWE
  • CWE-1059 - Insufficient Technical Documentation
Summary
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Impacted products
Vendor Product Version
Apache Software Foundation Apache Tomcat Version: 11.0.0-M1    11.0.23
Version: 10.1.0-M1    10.1.56
Version: 9.0.13    9.0.119
Version: 8.5.38    8.5.100
Version: 7.0.100    7.0.109
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2026-07-14T10:33:10.332Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/07/14/8"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 9.1,
              "baseSeverity": "CRITICAL",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-59084",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-14T13:51:48.818351Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-14T13:51:52.489Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Apache Tomcat",
          "vendor": "Apache Software Foundation",
          "versions": [
            {
              "lessThanOrEqual": "11.0.23",
              "status": "affected",
              "version": "11.0.0-M1",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "10.1.56",
              "status": "affected",
              "version": "10.1.0-M1",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "9.0.119",
              "status": "affected",
              "version": "9.0.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "8.5.100",
              "status": "affected",
              "version": "8.5.38",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.109",
              "status": "affected",
              "version": "7.0.100",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "NDIx"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eInsufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.\u003c/p\u003e\u003cp\u003eThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\u0026nbsp;Other versions that have reached end of support may also be affected.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.\u003c/p\u003e"
            }
          ],
          "value": "Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\u00a0Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue."
        }
      ],
      "metrics": [
        {
          "other": {
            "content": {
              "text": "low"
            },
            "type": "Textual description of severity"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1059",
              "description": "CWE-1059 Insufficient Technical Documentation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-14T08:24:21.531Z",
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "shortName": "apache"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Apache Tomcat: EncryptInterceptor requirements not clearly documented",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "assignerShortName": "apache",
    "cveId": "CVE-2026-59084",
    "datePublished": "2026-07-14T08:24:21.531Z",
    "dateReserved": "2026-07-02T10:42:32.668Z",
    "dateUpdated": "2026-07-14T13:51:52.489Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation

Phases: Documentation, Architecture and Design

Description:

  • Ensure that design documentation is detailed enough to allow for post-manufacturing verification.

No CAPEC attack patterns related to this CWE.

Back to CWE stats page