PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0694 CODESYS CVE debrief

CVE-2025-0694 is an ICS vulnerability in CODESYS Control as distributed with Festo Automation Suite. The advisory says a low-privileged attacker with physical access can exploit insufficient path validation to gain full filesystem access. CISA first published the advisory on 2026-02-26 and later republished the Festo advisory on 2026-03-17.

Vendor
CODESYS
Product
FESTO
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-03-17
Advisory published
2026-02-26
Advisory updated
2026-03-17

Who should care

OT/ICS teams running Festo Automation Suite, especially systems that include CODESYS components, should review this issue. It is most relevant where physical access to engineering workstations or other affected systems is possible.

Technical summary

The supplied advisory describes insufficient path validation in CODESYS Control. In practical terms, the flaw can let a low-privileged attacker with physical access break out of the intended file path restrictions and access the full filesystem. The advisory maps the issue to CWE-22 and gives a CVSS v3.1 vector of AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (6.6).

Defensive priority

Medium. The attack requires physical access, but the potential impact is high because filesystem exposure can affect confidentiality, integrity, and availability on the affected system.

Recommended defensive actions

  • Install the latest patched CODESYS release from the official CODESYS website.
  • Follow the vendor's installation and update guidance so all security fixes are applied.
  • Update the Festo Automation Suite connector using the latest Festo release.
  • Check whether your environment uses the affected Festo Automation Suite/CODESYS combinations identified in the advisory.
  • Restrict physical access to affected engineering or OT systems and monitor vendor security advisories closely.

Evidence notes

Facts are drawn from the supplied CISA CSAF advisory ICSA-26-076-01 and its referenced Festo/CERT-VDE materials. The record identifies the issue as 'CODESYS in Festo Automation Suite' and describes insufficient path validation with physical-access, low-privilege impact. The supplied vendor/product metadata is inconsistent, so attribution should be reviewed before external reporting.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-0694 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-0694

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-0694 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0694

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.