PatchSiren cyber security CVE debrief
CVE-2022-47378 CODESYS CVE debrief
CVE-2022-47378 is an authenticated remote denial-of-service vulnerability caused by improper input validation in multiple CODESYS products used in the Festo Automation Suite ecosystem. According to the CISA-republished advisory, an attacker with valid access can craft specific requests that trigger a service disruption. The issue was published on 2026-02-26 and later republished/updated on 2026-03-17 with the initial CISA republication of the Festo advisory.
- Vendor
- CODESYS
- Product
- FESTO
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-11
- Original CVE updated
- 2026-01-20
- Advisory published
- 2023-07-11
- Advisory updated
- 2026-01-20
Who should care
OT/ICS operators, engineering teams, and asset owners running Festo Automation Suite deployments that include bundled CODESYS components should review exposure. Security teams responsible for industrial engineering workstations and remote-access paths should also pay attention because exploitation requires authentication but can still cause operational downtime.
Technical summary
The advisory describes an improper input validation flaw in multiple CODESYS products. The practical impact is denial of service only: a remote authenticated attacker may send crafted requests that cause the affected component to stop functioning or become unavailable. CISA’s advisory ties the issue to Festo Automation Suite versions below 2.8.0.138 and to bundled CODESYS Development System components listed in the source record. No confidentiality or integrity impact is indicated in the supplied material.
Defensive priority
Medium. The vulnerability is network-reachable and can disrupt availability, but it requires authentication and is not marked as KEV. Prioritize remediation for exposed engineering environments and any systems where downtime would affect operations.
Recommended defensive actions
- Inventory Festo Automation Suite installations and identify whether they include the CODESYS components named in the advisory.
- Upgrade to the latest patched CODESYS release from the official CODESYS website, following the vendor’s installation and update guidance.
- Apply Festo Automation Suite updates promptly, and confirm the connector remains current with vendor releases.
- Review access controls around engineering workstations and remote administration paths so authenticated access is limited to trusted users.
- Monitor CODESYS and Festo security advisories for follow-on updates or revised remediation guidance.
Evidence notes
The source corpus states that multiple CODESYS products in multiple versions are affected by improper input validation and that an authenticated remote attacker can craft requests leading to denial of service. The CISA source item republished the Festo advisory on 2026-02-26 and recorded a republication update on 2026-03-17. The advisory metadata also lists remediation guidance to update CODESYS separately and keep the Festo Automation Suite connector current. Vendor attribution in the supplied data is low-confidence and should be reviewed; the most reliable scope signal is the CISA advisory title and its referenced Festo/CODESYS remediation language.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-47378 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-47378
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-47378 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-47378
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.