PatchSiren

CODESYS CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37559

CVE-2023-37559 affects Festo Automation Suite deployments that include CODESYS components. After a user successfully authenticates, crafted network communication requests with inconsistent content can cause the CmpAppForce component to read from an invalid address and potentially deny service. The issue is availability-only, but that still matters in industrial environments where a service interruption ca [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37558

CVE-2023-37558 is an authenticated denial-of-service issue affecting multiple CODESYS products and versions as distributed with Festo Automation Suite. A user who has already authenticated can send crafted network communication requests with inconsistent content and cause the CmpAppForce component to read from an invalid address, potentially disrupting availability. The issue is distinct from CVE-2023-37559.

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37557

CVE-2023-37557 is an authenticated denial-of-service issue in CODESYS components used with Festo Automation Suite. According to the CISA CSAF advisory, crafted remote communication requests can make the CmpAppBP component overwrite a heap-based buffer, which can crash the affected service. The advisory was initially published by CISA on 2026-02-26 and later republished on 2026-03-17 from Festo’s original advisory.

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37556

CVE-2023-37556 affects multiple versions of CODESYS-related products used with Festo Automation Suite. After successful authentication, crafted network communication requests with inconsistent content can cause the CmpAppBP component to read from an invalid address, which may result in a denial-of-service condition. CISA published the advisory on 2026-02-26 and republished it on 2026-03-17.

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37555

CVE-2023-37555 is a medium-severity availability issue in CODESYS components used with Festo Automation Suite. After successful authentication, specially crafted network communication requests with inconsistent content can cause the CmpAppBP component to read from an invalid internal address, potentially resulting in denial of service. The advisory explicitly says this issue is different from CVE-2023-375 [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37554

CVE-2023-37554 affects multiple versions of CODESYS components used with Festo Automation Suite. After successful authentication, a crafted network communication request with inconsistent content can make the CmpAppBP component read from an invalid internal address, which may crash the service and cause denial of service. The advisory is distinct from CVE-2023-37552, CVE-2023-37553, CVE-2023-37555, and CV [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37553

CVE-2023-37553 affects multiple versions of CODESYS products used in Festo Automation Suite. A successful authenticated user can send specially crafted network communication requests with inconsistent content that cause the CmpAppBP component to read from an invalid internal address, creating a denial-of-service risk. The advisory is tied to Festo Automation Suite/CODESYS deployments rather than a standal [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37552

CVE-2023-37552 is an authenticated denial-of-service issue affecting multiple CODESYS products as deployed with Festo Automation Suite. The advisory says that, after successful user authentication, specially crafted network communication requests with inconsistent content can make the CmpAppBP component read from an invalid internal address, potentially crashing or otherwise denying service. CISA publishe [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37550

CVE-2023-37550 is a post-authentication denial-of-service issue affecting multiple CODESYS product combinations used with Festo Automation Suite. The advisory says that crafted network communication requests with inconsistent content can make the CmpApp component read from an invalid address, which can disrupt availability. The source also lists impacted Festo Automation Suite releases below 2.8.0.138 and [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37549

CVE-2023-37549 is an authenticated remote denial-of-service issue affecting multiple CODESYS product versions used in Festo Automation Suite. According to the advisory, specially crafted network communication requests with inconsistent content can make the CmpApp component read from an invalid internal address, which can disrupt the service and potentially stop affected systems from operating normally.

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37548

CVE-2023-37548 is an availability issue in multiple CODESYS-related products used with Festo Automation Suite. After a user successfully authenticates, specially crafted network communication requests with inconsistent content can make the CmpApp component read from an invalid address, which can lead to a denial-of-service condition. The advisory describes this as a distinct issue from neighboring CODESYS [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37547

CVE-2023-37547 describes an authenticated denial-of-service condition affecting multiple CODESYS products and versions as used in Festo Automation Suite. According to the advisory, a user who has already authenticated can send crafted network communication requests with inconsistent content that cause the CmpApp component to read from an invalid internal address, potentially crashing or destabilizing the [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37546

CVE-2023-37546 affects multiple CODESYS products and Festo Automation Suite deployments that bundle specific CODESYS versions. After successful user authentication, crafted network communication requests with inconsistent content can make the CmpApp component read from an invalid internal address, which can lead to a denial-of-service condition. The issue is documented in CISA’s republication of the Festo [truncated]

MEDIUM CODESYS CVE published 2025-04-10

CVE-2023-37545

CVE-2023-37545 is a medium-severity denial-of-service issue in CODESYS components used in Festo Automation Suite. According to the advisory, a user who has already authenticated can send specific crafted network communication requests with inconsistent content and cause the CmpApp component to read from an invalid internal address. The practical outcome is a crash or service disruption rather than a direc [truncated]

HIGH CODESYS CVE published 2024-12-03

CVE-2022-31804

CVE-2022-31804 is a network-exploitable denial-of-service issue in CODESYS Gateway Server V2 used by FESTO's "CODESYS provided by Festo" software. The gateway does not verify that request size stays within expected limits, so an unauthenticated attacker can force arbitrary memory allocation and potentially crash the service through out-of-memory exhaustion. The supplied CVSS vector is AV:N/AC:L/PR:N/UI:N/ [truncated]

MEDIUM CODESYS CVE published 2024-12-03

CVE-2022-31803

CVE-2022-31803 affects FESTO’s CODESYS provided by Festo deployments and is described by CISA as a flaw in CODESYS Gateway Server V2 that lets an unauthenticated attacker consume all available TCP connections. The impact is availability-only: legitimate users or clients may be unable to establish new connections, while existing connections remain intact. CISA’s CSAF advisory rates the issue medium severit [truncated]

CRITICAL CODESYS CVE published 2024-12-03

CVE-2022-31802

CVE-2022-31802 is a critical authentication bypass affecting CODESYS Gateway Server V2 in Festo-related software. According to the supplied CSAF description, versions prior to V2.3.9.38 compare only part of the provided password against the real gateway password, which can let an attacker authenticate with a shorter password that matches the compared portion. The result is a network-reachable, unauthentic [truncated]

MEDIUM CODESYS CVE published 2023-07-11

CVE-2023-37551

CVE-2023-37551 affects CODESYS components used in Festo Automation Suite deployments. After successful authentication as a user, specially crafted network requests can use the CmpApp component to download files with any extension to the controller, bypassing the file-type filtering applied by CmpFileTransfer. The advisory says this can compromise the integrity of the CODESYS control runtime system.

HIGH CODESYS CVE published 2023-07-11

CVE-2023-3670

CVE-2023-3670 describes an unsafe directory-permissions issue in CODESYS Development System and CODESYS Scripting. On affected workstation installations, a locally present attacker could place disguised scripts in locations that legitimate users later trust and run, creating a path to unauthorized code execution in an engineering environment. The supplied advisory ties the issue to CODESYS components refe [truncated]

LOW CODESYS CVE published 2023-07-11

CVE-2023-3669

CVE-2023-3669 is a low-severity local brute-force weakness in CODESYS Development System prior to 3.5.19.20. The issue allows unlimited password guesses within an import dialog, which can weaken the confidentiality of protected imported content. In the supplied source corpus, CISA republished the Festo advisory for this issue on 2026-02-26 and updated the record on 2026-03-17.

HIGH CODESYS CVE published 2023-07-11

CVE-2023-3663

CVE-2023-3663 is a high-severity issue in CODESYS Development System where a missing integrity check may allow an unauthenticated remote attacker to manipulate notification content received over HTTP by the CODESYS notification server. The advisory context in the supplied source is tied to Festo Automation Suite deployments that include CODESYS components, but the vulnerability statement itself is specifi [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2023-3662

CVE-2023-3662 is a local code-execution issue tied to CODESYS Development System components used with Festo Automation Suite. The advisory states that binaries from the current working directory can be executed in the user’s context, which can let an attacker influence what runs when a user launches the affected software from a writable location. The published CVSS 3.1 score is 7.3 (High), but the vector [truncated]

MEDIUM CODESYS CVE published 2023-07-11

CVE-2022-47393

CVE-2022-47393 is a denial-of-service issue in multiple CODESYS product versions used with Festo Automation Suite. According to the CISA CSAF advisory, an authenticated remote attacker can exploit an improper memory-buffer bounds restriction to force service disruption. The advisory was first published on 2026-02-26 and republished on 2026-03-17 with the initial CISA republication of the Festo advisory.

MEDIUM CODESYS CVE published 2023-07-11

CVE-2022-47392

CVE-2022-47392 is a medium-severity availability issue affecting CmpApp/CmpAppBP/CmpAppForce components in multiple CODESYS products used by Festo Automation Suite. According to the advisory, an authenticated remote attacker can exploit improper input validation to read from an invalid address, which can lead to a denial-of-service condition.

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47391

CVE-2022-47391 is a high-severity denial-of-service issue affecting multiple CODESYS products and versions as distributed in Festo Automation Suite. According to the advisory, an unauthorized remote attacker may exploit improper input validation to read from invalid addresses, resulting in service disruption. The practical risk is highest for environments that use affected Festo Automation Suite releases [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47390

CVE-2022-47390 is an authenticated, remote stack-based out-of-bounds write in the CmpTraceMgr component used by multiple CODESYS product versions, including CODESYS components associated with Festo Automation Suite. CISA rates the issue 8.8 High and notes impacts that can range from denial of service to memory overwriting and remote code execution. The defensive priority is high because the vulnerable pat [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47389

CVE-2022-47389 is a high-severity memory corruption issue in the CmpTraceMgr component used by certain CODESYS products in Festo Automation Suite deployments. According to the CISA CSAF advisory, an authenticated remote attacker could trigger a stack-based out-of-bounds write that may lead to denial of service, memory overwriting, or remote code execution.

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47388

CVE-2022-47388 is a high-severity memory corruption flaw in the CmpTraceMgr component used by multiple CODESYS products. In the Festo Automation Suite context, an authenticated remote attacker may be able to write past the stack boundary, which can result in denial of service, memory overwriting, or remote code execution. The advisory recommends moving to patched CODESYS releases and keeping the Festo Aut [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47387

CVE-2022-47387 is a high-severity stack-based out-of-bounds write in the CmpTraceMgr component used by CODESYS products in Festo Automation Suite. According to the CISA republication of the vendor advisory, an authenticated remote attacker may be able to trigger denial of service, memory overwriting, or remote code execution. The advisory was initially published on 2026-02-26 and revised on 2026-03-17.

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47386

CVE-2022-47386 is a high-severity memory corruption issue reported by CISA for CODESYS components used in Festo Automation Suite. The advisory says an authenticated remote attacker could trigger a stack-based out-of-bounds write in the CmpTraceMgr component, which may lead to denial of service, memory overwriting, or remote code execution. CISA published the advisory on 2026-02-26 and republished it on 20 [truncated]