PatchSiren cyber security CVE debrief
CVE-2019-18858 Festo CVE debrief
CVE-2019-18858 is a critical buffer overflow in the CODESYS 3 web server before 3.5.15.20. In the CISA CSAF advisory republished from Festo/CERT@VDE, the issue is tied to Festo Automation Suite deployments that include CODESYS components. Because the CVSS vector is network-based with no privileges or user interaction required, and the potential impact is high across confidentiality, integrity, and availability, this should be treated as a high-priority OT/ICS patching issue.
- Vendor
- Festo
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-09-30
- Original CVE updated
- 2025-11-13
- Advisory published
- 2025-09-30
- Advisory updated
- 2025-11-13
Who should care
OT/ICS operators using Festo Automation Suite, administrators of CODESYS-based control or runtime environments, and asset owners responsible for engineering workstations or distributed runtime systems that may include bundled CODESYS components.
Technical summary
The source advisory states that CODESYS 3 web server versions before 3.5.15.20 are affected by a buffer overflow. The advisory scope includes Festo Automation Suite installations that bundled CODESYS components, and it notes that starting with Festo Automation Suite 2.8.0.138, CODESYS is no longer bundled and must be installed separately. The supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a remotely reachable issue with severe impact potential if exploited.
Defensive priority
Critical
Recommended defensive actions
- Inventory Festo Automation Suite and CODESYS installations to identify affected versions and bundled components.
- Apply vendor updates so the CODESYS component is at or above version 3.5.15.20.
- Move Festo Automation Suite to 2.8.0.138 or later where applicable, and verify any separately installed CODESYS package is patched through official vendor channels.
- Follow the installation and update instructions published by CODESYS and Festo rather than using ad hoc package sources.
- Monitor CISA, Festo PSIRT, and CERT@VDE advisories for follow-on revisions or scope changes.
Evidence notes
CISA's CSAF advisory ICSA-26-076-01 republishes the Festo SE & Co. KG advisory FSA-202601 and directly states the vulnerable component as 'CODESYS 3 web server before 3.5.15.20.' The source metadata also says that from Festo Automation Suite 2.8.0.138 onward, CODESYS is no longer bundled and must be installed separately. The prompt's vendor mapping is low-confidence and should be reviewed against the Festo/CERT@VDE references.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-18858 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-18858
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-18858 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-18858
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-273-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-273-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.