PatchSiren cyber security CVE debrief
CVE-2022-47386 CODESYS CVE debrief
CVE-2022-47386 is a high-severity memory corruption issue reported by CISA for CODESYS components used in Festo Automation Suite. The advisory says an authenticated remote attacker could trigger a stack-based out-of-bounds write in the CmpTraceMgr component, which may lead to denial of service, memory overwriting, or remote code execution. CISA published the advisory on 2026-02-26 and republished it on 2026-03-17 with the initial Festo/CERT-VDE advisory content.
- Vendor
- CODESYS
- Product
- FESTO
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-11
- Original CVE updated
- 2026-01-20
- Advisory published
- 2023-07-11
- Advisory updated
- 2026-01-20
Who should care
Organizations using Festo Automation Suite installations that bundle or rely on CODESYS components, especially environments listed in the advisory as affected versions. OT/ICS operators, automation engineers, and vulnerability management teams should prioritize review because the issue is remotely reachable with authentication and can affect confidentiality, integrity, and availability.
Technical summary
The source advisory describes a stack-based out-of-bounds write in CmpTraceMgr within multiple CODESYS products and versions. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network exposure, low attack complexity, and required low privileges. Affected configurations include Festo Automation Suite versions below 2.8.0.138 and listed installations that include CODESYS Development System 3.0, 3.5.16.10, or 3.5.21.20 as documented in the advisory metadata.
Defensive priority
High. This is a remotely reachable memory corruption flaw with potential for service disruption and code execution. If affected systems are exposed to untrusted networks or rely on authenticated remote access, prioritize patching and configuration review promptly.
Recommended defensive actions
- Update Festo Automation Suite to a version at or above 2.8.0.138 where the bundled CODESYS behavior changed per the advisory.
- Install the latest patched CODESYS version directly from the official CODESYS website, following vendor installation and update guidance.
- Review whether any affected installations use the listed CODESYS Development System versions or external components identified in the advisory.
- Monitor Festo and CODESYS security advisories and apply updates promptly when new fixes are released.
- Keep the Festo Automation Suite connector current by installing FAS updates as they are released by Festo.
- Treat remote authenticated access paths to affected automation hosts as sensitive and restrict them to trusted administrative users and networks while remediation is underway.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-076-01 and its referenced Festo/CERT-VDE materials. The advisory title is 'CODESYS in Festo Automation Suite.' The described vulnerability is an authenticated remote stack-based out-of-bounds write in CmpTraceMgr. The source metadata lists affected product combinations including Festo Automation Suite <2.8.0.138 and installations involving CODESYS Development System 3.0, 3.5.16.10, and 3.5.21.20. The supplied CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, and no KEV entry was provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-47386 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-47386
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-47386 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-47386
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.