PatchSiren cyber security CVE debrief
CVE-2022-47391 CODESYS CVE debrief
CVE-2022-47391 is a high-severity denial-of-service issue affecting multiple CODESYS products and versions as distributed in Festo Automation Suite. According to the advisory, an unauthorized remote attacker may exploit improper input validation to read from invalid addresses, resulting in service disruption. The practical risk is highest for environments that use affected Festo Automation Suite releases with bundled or separately installed CODESYS components.
- Vendor
- CODESYS
- Product
- FESTO
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-11
- Original CVE updated
- 2026-01-20
- Advisory published
- 2023-07-11
- Advisory updated
- 2026-01-20
Who should care
OT/ICS administrators, engineers, and support teams using Festo Automation Suite and CODESYS Development System installations should review this advisory. It is especially relevant for organizations that rely on affected suite versions or CODESYS components in operational workflows, where a remote denial of service could interrupt engineering or control-related activities.
Technical summary
The advisory describes an improper input validation flaw in multiple CODESYS products and versions. The issue is reachable remotely without authorization and can cause reads from invalid memory addresses, which in turn leads to denial of service. The CISA CSAF record ties the issue to Festo Automation Suite deployments that include affected CODESYS components, including versions prior to 2.8.0.138 and specific bundled CODESYS Development System releases. Festo notes that starting with Festo Automation Suite 2.8.0.138, CODESYS is no longer bundled and must be downloaded and installed separately.
Defensive priority
High for affected environments that expose or rely on the vulnerable CODESYS components. Because the impact is availability-only but remotely reachable and unauthenticated, patching and version verification should be prioritized for any production or engineering system using the affected software stack.
Recommended defensive actions
- Verify whether Festo Automation Suite installations include affected CODESYS components and map them to the versions listed in the advisory.
- Update to Festo Automation Suite 2.8.0.138 or later where applicable, and confirm which CODESYS component version is installed separately.
- Install the latest patched CODESYS release directly from the official CODESYS website, following vendor installation and update instructions.
- Keep the Festo Automation Suite connector updated by applying Festo releases as they are issued.
- Monitor CODESYS and Festo security advisories for follow-up fixes and configuration guidance.
- Validate that affected engineering workstations and related systems are not running outdated bundled or manually installed CODESYS components.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-26-076-01 republished from Festo/CERT-VDE, which states that an unauthorized remote attacker may use improper input validation to read from invalid addresses and cause denial of service. The advisory also lists affected Festo Automation Suite and CODESYS versions, and provides mitigation guidance to update Festo Automation Suite and install patched CODESYS releases from the official source.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-47391 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-47391
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-47391 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-47391
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.