PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-47393 CODESYS CVE debrief

CVE-2022-47393 is a denial-of-service issue in multiple CODESYS product versions used with Festo Automation Suite. According to the CISA CSAF advisory, an authenticated remote attacker can exploit an improper memory-buffer bounds restriction to force service disruption. The advisory was first published on 2026-02-26 and republished on 2026-03-17 with the initial CISA republication of the Festo advisory.

Vendor
CODESYS
Product
FESTO
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2023-07-11
Original CVE updated
2026-01-20
Advisory published
2023-07-11
Advisory updated
2026-01-20

Who should care

Organizations running Festo Automation Suite with bundled or separately installed CODESYS components, especially OT/ICS teams, engineering workstations, and administrators responsible for patching industrial software.

Technical summary

The advisory describes an authenticated, remote attack path against multiple versions of multiple CODESYS products, resulting in denial of service. The supplied CVSS v3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates network reachability, low attack complexity, low privileges required, no user interaction, and high availability impact, with no confidentiality or integrity impact noted.

Defensive priority

Medium. The issue is exploitable over the network by an authenticated attacker and can disrupt availability, so it should be prioritized for affected engineering and OT environments.

Recommended defensive actions

  • Update Festo Automation Suite to version 2.8.0.138 or later, as the advisory notes that this release stops bundling CODESYS and requires separate installation.
  • Install the latest patched CODESYS version directly from the official CODESYS website and follow the vendor's update instructions.
  • Review all systems using Festo Automation Suite for bundled or separately installed CODESYS components, including the specific versions listed in the advisory.
  • Monitor CODESYS and Festo security advisories and apply updates promptly.
  • Keep the Festo Automation Suite connector current by installing FAS updates as released by Festo.

Evidence notes

The source is the CISA CSAF advisory ICSA-26-076-01, republishing Festo's FSA-202601 advisory. The advisory title is 'CODESYS in Festo Automation Suite' and lists affected combinations involving Festo Automation Suite and CODESYS Development System. It states that an authenticated remote attacker may use an improper restriction of operations within the bounds of a memory buffer to force denial of service. The supplied CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-47393 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-47393

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-47393 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-47393

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.