PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-37553 CODESYS CVE debrief

CVE-2023-37553 affects multiple versions of CODESYS products used in Festo Automation Suite. A successful authenticated user can send specially crafted network communication requests with inconsistent content that cause the CmpAppBP component to read from an invalid internal address, creating a denial-of-service risk. The advisory is tied to Festo Automation Suite/CODESYS deployments rather than a standalone internet-facing service.

Vendor
CODESYS
Product
FESTO
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-10
Original CVE updated
2025-04-10
Advisory published
2025-04-10
Advisory updated
2025-04-10

Who should care

OT administrators, industrial control engineers, and security teams responsible for Festo Automation Suite installations and any affected CODESYS components. This is especially relevant where CODESYS is bundled with or separately installed alongside Festo Automation Suite and where authenticated users can reach the affected network interface.

Technical summary

The source advisory describes an authenticated, network-reachable flaw in CmpAppBP: crafted requests with inconsistent content can trigger an invalid internal address read. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with a medium-severity availability impact rather than confidentiality or integrity impact. Affected products in the source include Festo Automation Suite versions below 2.8.0.138 and specific CODESYS Development System combinations listed in the advisory.

Defensive priority

Medium. Prioritize remediation on affected Festo Automation Suite/CODESYS systems because the issue is network-reachable after authentication and can disrupt availability. If the component is exposed to multiple trusted users or shared operational environments, treat it as a higher operational risk.

Recommended defensive actions

  • Upgrade to a patched CODESYS release obtained from the official CODESYS source referenced in the advisory.
  • Apply Festo Automation Suite updates promptly, including the connector updates Festo releases for the suite.
  • Verify whether your Festo Automation Suite installation includes affected bundled or separately installed CODESYS components.
  • Restrict authenticated access to the affected network path to only necessary operators and systems.
  • Monitor CODESYS and Festo security advisories for follow-on fixes or revised affected-version guidance.
  • Document which systems are on Festo Automation Suite 2.8.0.137 or earlier and schedule remediation first for exposed or production OT assets.

Evidence notes

All claims here are taken from the supplied CISA CSAF advisory and its referenced official sources. The advisory states that, after successful authentication, crafted network communication requests with inconsistent content can cause CmpAppBP to read from an invalid address, potentially resulting in denial of service. The supplied remediation text states that from Festo Automation Suite 2.8.0.138 onward, CODESYS is no longer bundled and that customers should install patched CODESYS versions and keep the FAS connector updated. The vendor mapping in the provided data is low-confidence and should be validated before use in asset inventories.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-37553 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-37553

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-37553 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-37553

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.