PatchSiren cyber security CVE debrief
CVE-2018-10612 3S-Smart CVE debrief
CISA's ICSA-26-076-01, published 2026-02-26 and revised 2026-03-17, covers CVE-2018-10612 in CODESYS Control V3 products prior to 3.5.14.0. Because user access management and communication encryption are not enabled by default, an attacker may gain access to the device and sensitive information, including user credentials. Systems using Festo Automation Suite bundles should move to patched CODESYS/Festo releases and confirm the vulnerable component is no longer present.
- Vendor
- 3S-Smart
- Product
- FESTO
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-09-30
- Original CVE updated
- 2025-11-13
- Advisory published
- 2025-09-30
- Advisory updated
- 2025-11-13
Who should care
OT/ICS teams, system integrators, and engineers running Festo Automation Suite installations that include CODESYS components, especially where CODESYS Control V3 devices may be reachable from the network.
Technical summary
The advisory describes a default security configuration problem in CODESYS Control V3 prior to version 3.5.14.0: user access management and communication encryption are not enabled by default. CISA maps the issue to CWE-284 and rates it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating that remote attackers could access the device and sensitive data, including credentials, without authentication.
Defensive priority
Urgent: treat as a critical OT exposure and prioritize patching, component verification, and exposure review immediately.
Recommended defensive actions
- Identify Festo Automation Suite installations that bundle CODESYS components and confirm whether they are below version 2.8.0.138.
- Upgrade to the latest patched CODESYS release from the official CODESYS website, following the vendor's installation and update instructions.
- Update Festo Automation Suite to the latest available release and keep the FAS connector current.
- Verify that CODESYS Control V3 instances are at or above version 3.5.14.0 or otherwise no longer rely on the vulnerable default configuration.
- Monitor official CODESYS and Festo advisories for follow-on fixes and apply updates promptly.
Evidence notes
The source advisory title is 'CODESYS in Festo Automation Suite.' Its description states that CODESYS Control V3 products prior to 3.5.14.0 do not enable user access management or communication encryption by default, which can expose devices and credentials. The advisory metadata also lists affected Festo Automation Suite versions and shows publication on 2026-02-26 with a republication/revision on 2026-03-17.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-10612 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-10612
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-10612 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-10612
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.