PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-13542 GmbH CVE debrief

This vulnerability can let an attacker who can act as a trusted OPC UA client send crafted requests that trigger a NULL pointer dereference in CODESYS V3 OPC UA Server, resulting in a denial-of-service condition. The source advisory ties the issue to CODESYS use within Festo Automation Suite, and notes that Festo Automation Suite 2.8.0.138 no longer bundles CODESYS.

Vendor
GmbH
Product
FESTO
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-09-30
Original CVE updated
2025-11-13
Advisory published
2025-09-30
Advisory updated
2025-11-13

Who should care

OT and industrial control system operators using CODESYS V3 OPC UA Server versions 3.5.11.0 through 3.5.15.0, especially where the component is deployed through Festo Automation Suite or where trusted OPC UA client access is allowed.

Technical summary

CISA’s CSAF advisory states that CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows crafted requests from a trusted OPC UA client to cause a NULL pointer dereference. The described impact is denial of service, and the provided CVSS vector reflects network reachability with low attack complexity, low privileges, no user interaction, and high availability impact. The source advisory also states that from Festo Automation Suite 2.8.0.138 onward, CODESYS is no longer bundled and must be obtained separately.

Defensive priority

Medium. The issue is availability-impacting rather than a confirmed code-execution flaw, but it affects industrial software and can be triggered over networked OPC UA paths by an attacker with trusted-client access.

Recommended defensive actions

  • Verify whether your environment uses CODESYS V3 OPC UA Server versions 3.5.11.0 through 3.5.15.0 or Festo Automation Suite releases that bundle CODESYS.
  • Apply the latest patched CODESYS release from the official CODESYS website as directed in the advisory.
  • If using Festo Automation Suite, install the latest FAS updates and confirm whether your deployed version still bundles CODESYS.
  • Review OPC UA trust relationships and restrict trusted-client access to only necessary systems.
  • Monitor vendor and CISA advisories for follow-on guidance and validation of affected product combinations.

Evidence notes

Based on the supplied CISA CSAF source item (ICSA-26-076-01) republished on 2026-02-26 and updated on 2026-03-17. The advisory explicitly names CODESYS V3 OPC UA Server versions 3.5.11.0 through 3.5.15.0 and describes a NULL pointer dereference leading to denial of service. The same source notes that Festo Automation Suite 2.8.0.138 stops bundling CODESYS and that customers should install patched CODESYS releases from the official vendor site.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-13542 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-13542

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-13542 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-13542

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.