PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-47389 CODESYS CVE debrief

CVE-2022-47389 is a high-severity memory corruption issue in the CmpTraceMgr component used by certain CODESYS products in Festo Automation Suite deployments. According to the CISA CSAF advisory, an authenticated remote attacker could trigger a stack-based out-of-bounds write that may lead to denial of service, memory overwriting, or remote code execution.

Vendor
CODESYS
Product
FESTO
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2023-07-11
Original CVE updated
2026-01-20
Advisory published
2023-07-11
Advisory updated
2026-01-20

Who should care

Administrators and defenders responsible for Festo Automation Suite installations, especially environments that bundle or depend on affected CODESYS components, should review exposure and patch status.

Technical summary

The advisory identifies a stack-based out-of-bounds write in the CmpTraceMgr component of multiple CODESYS products. CISA's affected-product list includes Festo Automation Suite <2.8.0.138 with CODESYS Development System 3.0 or 3.5.16.10, Festo Automation Suite 2.8.0.137 with those same CODESYS versions, and CODESYS Development System 3.5.21.20 as an external component of Festo Automation Suite 2.8.0.138. The stated impact is denial of service, memory corruption, and possible remote code execution from an authenticated remote attacker.

Defensive priority

High. The combination of network attack surface, low attack complexity, required authentication, and potential RCE makes this a priority patching issue for affected deployments.

Recommended defensive actions

  • Identify whether Festo Automation Suite is installed and verify the exact bundled or external CODESYS component version.
  • Upgrade to Festo Automation Suite 2.8.0.138 or later and follow Festo's and CODESYS's current installation/update guidance.
  • Download patched CODESYS releases only from the official CODESYS website, as recommended in the advisory.
  • Apply Festo Automation Suite connector updates when released and keep both the suite and dependent components current.
  • Review access controls for authenticated remote access paths to affected systems and limit them to necessary administrators.
  • Monitor CISA, CERT@VDE, Festo PSIRT, and CODESYS security advisories for follow-up guidance.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-26-076-01 and its source references. The advisory text explicitly names the CmpTraceMgr stack-based out-of-bounds write, the impacted Festo Automation Suite/CODESYS version combinations, and the vendor-recommended mitigations. The supplied materials do not include exploit code or public weaponization details.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-47389 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-47389

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-47389 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-47389

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.