PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-32138 Unknown Vendor CVE debrief

CVE-2022-32138 affects multiple CODESYS components used with Festo Automation Suite. A remote attacker with low privileges may send a crafted request that triggers an unexpected sign extension, which can cause a denial-of-service condition or memory overwrite. The issue was published in the CISA-republished CSAF advisory ICSA-26-076-01 on 2026-02-26 and updated on 2026-03-17.

Vendor
Unknown Vendor
Product
FESTO
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-26
Original CVE updated
2026-03-17
Advisory published
2026-02-26
Advisory updated
2026-03-17

Who should care

OT/ICS teams, Festo Automation Suite users, and engineers managing CODESYS development systems on Windows engineering workstations or similar hosts.

Technical summary

The advisory lists affected Festo Automation Suite deployments below 2.8.0.138 and associated CODESYS Development System components, including 3.0, 3.5.16.10, and 3.5.21.20 in the documented product combinations. The flaw is an unexpected sign extension in request handling; the vendor advisory describes outcomes ranging from denial of service to memory overwrite. No exploit details are provided in the source corpus.

Defensive priority

High

Recommended defensive actions

  • Upgrade Festo Automation Suite to 2.8.0.138 or later, where bundled CODESYS is no longer included.
  • Install the latest patched CODESYS release directly from the official CODESYS website and follow the vendor's update instructions.
  • Verify affected engineering workstations and deployments for bundled or separately installed CODESYS components and replace outdated versions.
  • Keep the Festo Automation Suite connector up to date using Festo-released updates.
  • Monitor CODESYS and Festo security advisories and apply fixes promptly.

Evidence notes

Based on the CISA CSAF advisory ICSA-26-076-01 (republished from Festo advisory FSA-202601) and the linked Festo/CERT VDE references. The source explicitly names Festo Automation Suite versions below 2.8.0.138 and associated CODESYS versions as affected, and states the issue can cause DoS or memory overwrite.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-32138 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-32138

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-32138 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-32138

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.