PatchSiren cyber security CVE debrief
CVE-2022-32138 Unknown Vendor CVE debrief
CVE-2022-32138 affects multiple CODESYS components used with Festo Automation Suite. A remote attacker with low privileges may send a crafted request that triggers an unexpected sign extension, which can cause a denial-of-service condition or memory overwrite. The issue was published in the CISA-republished CSAF advisory ICSA-26-076-01 on 2026-02-26 and updated on 2026-03-17.
- Vendor
- Unknown Vendor
- Product
- FESTO
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-03-17
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-03-17
Who should care
OT/ICS teams, Festo Automation Suite users, and engineers managing CODESYS development systems on Windows engineering workstations or similar hosts.
Technical summary
The advisory lists affected Festo Automation Suite deployments below 2.8.0.138 and associated CODESYS Development System components, including 3.0, 3.5.16.10, and 3.5.21.20 in the documented product combinations. The flaw is an unexpected sign extension in request handling; the vendor advisory describes outcomes ranging from denial of service to memory overwrite. No exploit details are provided in the source corpus.
Defensive priority
High
Recommended defensive actions
- Upgrade Festo Automation Suite to 2.8.0.138 or later, where bundled CODESYS is no longer included.
- Install the latest patched CODESYS release directly from the official CODESYS website and follow the vendor's update instructions.
- Verify affected engineering workstations and deployments for bundled or separately installed CODESYS components and replace outdated versions.
- Keep the Festo Automation Suite connector up to date using Festo-released updates.
- Monitor CODESYS and Festo security advisories and apply fixes promptly.
Evidence notes
Based on the CISA CSAF advisory ICSA-26-076-01 (republished from Festo advisory FSA-202601) and the linked Festo/CERT VDE references. The source explicitly names Festo Automation Suite versions below 2.8.0.138 and associated CODESYS versions as affected, and states the issue can cause DoS or memory overwrite.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-32138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-32138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-32138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-32138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2025-108
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cve.org/CVERecord?id=CVE-2025-2595
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.