PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-49676 CODESYS CVE debrief

CVE-2023-49676 is a use-after-free vulnerability (CWE-416) in the CODESYS/Festo Automation Suite ecosystem. According to CISA's CSAF advisory ICSA-26-076-01, an unauthenticated local attacker can trick a user into opening a corrupted project file, which can crash the system. The advisory was published on 2026-02-26 and republished on 2026-03-17, and it ties remediation to updating Festo Automation Suite and installing patched CODESYS releases from official sources.

Vendor
CODESYS
Product
FESTO
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-03-17
Advisory published
2026-02-26
Advisory updated
2026-03-17

Who should care

OT administrators, automation engineers, and security teams supporting Festo Automation Suite or CODESYS Development System installations should care most. This is especially important where engineering project files may be exchanged with third parties or handled on shared workstations.

Technical summary

The advisory describes a local, user-interaction-required use-after-free condition with no confidentiality or integrity impact and high availability impact (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). The practical risk is disruption: opening a corrupted project file can crash the affected system. The supplied advisory scope includes Festo Automation Suite versions below 2.8.0.138 and related CODESYS Development System components named in the CSAF record.

Defensive priority

Medium. Prioritize patching on engineering and OT workstations because the issue can interrupt availability and requires only a user to open a malicious or corrupted project file. Raise priority if your environment regularly imports files from less-trusted sources.

Recommended defensive actions

  • Upgrade Festo Automation Suite to version 2.8.0.138 or later where applicable.
  • Install the latest patched CODESYS release directly from the official CODESYS website.
  • Follow the vendor's installation and update instructions so all security fixes are applied.
  • Keep the Festo Automation Suite connector current by applying FAS updates as they are released.
  • Review file-handling workflows for project files from external or untrusted sources and isolate or scan them before opening.
  • Monitor Festo PSIRT, CERT@VDE, and CISA advisories for bundle and component updates.

Evidence notes

Primary evidence comes from the CISA CSAF source item for ICSA-26-076-01, which republishes the Festo advisory and explicitly describes the use-after-free crash scenario, the user-interaction requirement, and the affected Festo/CODESYS product scope. The supplied metadata also lists the CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H and the CWE-416 reference. Vendor attribution in the prompt metadata is low-confidence and marked for review, so this debrief relies on the advisory text and official links rather than the placeholder vendor object.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-49676 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-49676

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-49676 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49676

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.