PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-29241 Festo CVE debrief

CVE-2021-29241 is a high-severity availability issue affecting CODESYS Gateway 3 before version 3.5.16.70. In the advisory republished by CISA for Festo Automation Suite environments, the flaw is described as a NULL pointer dereference that may result in denial of service. The issue matters most for industrial and OT deployments where interruption of engineering or gateway services can disrupt operations. The advisory was first published on 2026-02-26 and republished by CISA on 2026-03-17 with the original Festo advisory content.

Vendor
Festo
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-09-30
Original CVE updated
2025-11-13
Advisory published
2025-09-30
Advisory updated
2025-11-13

Who should care

OT/ICS administrators, Festo Automation Suite users, and teams responsible for CODESYS installations or updates should care most. Environments that rely on gateway availability, engineering connectivity, or tightly managed production systems should prioritize review.

Technical summary

The source advisory states that CODESYS Gateway 3 before 3.5.16.70 contains a NULL pointer dereference. The CVSS vector provided is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which aligns with a network-reachable, low-complexity denial-of-service condition without privileges or user interaction. The Festo advisory also notes that starting with Festo Automation Suite 2.8.0.138, CODESYS is no longer bundled and must be downloaded and installed separately; remediation therefore depends on keeping any separately installed CODESYS components patched and ensuring the Festo Automation Suite connector is current.

Defensive priority

High

Recommended defensive actions

  • Update any affected CODESYS Gateway 3 installation to version 3.5.16.70 or later.
  • If CODESYS is installed separately from Festo Automation Suite, obtain and install the latest patched version directly from the official CODESYS source.
  • Keep the Festo Automation Suite connector up to date by applying Festo-released updates.
  • Monitor vendor security advisories for both Festo and CODESYS and apply fixes promptly.
  • Inventory affected systems to confirm whether older bundled or separately installed CODESYS components are present.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-26-076-01 and its referenced Festo advisory materials. The source explicitly states that CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may cause denial of service. The advisory metadata also indicates that CISA republished the Festo SE & Co. KG advisory content on 2026-03-17. Note: the provided vendor metadata is inconsistent and marked low-confidence; the source advisory title is 'CODESYS in Festo Automation Suite,' so the product scope should be treated as Festo Automation Suite environments containing CODESYS components rather than FESTO as a standalone product.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-29241 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-29241

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-29241 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-29241

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-273-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-273-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.