PatchSiren

CODESYS CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47385

CVE-2022-47385 is a high-severity memory-corruption issue affecting CODESYS components used in multiple Festo Automation Suite versions. According to the CISA advisory, an authenticated remote attacker could trigger a stack-based out-of-bounds write in the CmpAppForce component, potentially causing denial of service, memory overwriting, or remote code execution. The advisory was initially published on 202 [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47384

CVE-2022-47384 is a high-severity memory-corruption issue in the CmpTraceMgr component used by multiple CODESYS products and Festo Automation Suite deployments that include CODESYS. According to the advisory, an authenticated remote attacker can write data into the stack, which may result in denial of service, memory overwriting, or remote code execution. The supplied CVSS vector indicates network attacka [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47381

CVE-2022-47381 is a high-severity flaw in CODESYS components used by Festo Automation Suite. The advisory says an authenticated remote attacker may trigger a stack-based out-of-bounds write, which can lead to denial of service, memory overwriting, or remote code execution. CISA published the advisory on 2026-02-26 and republished it with updated source material on 2026-03-17.

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47380

CVE-2022-47380 is a high-severity memory corruption issue affecting multiple CODESYS product versions used in Festo Automation Suite. According to the advisory, an authenticated remote attacker may trigger a stack-based out-of-bounds write, which can cause denial of service, memory overwriting, or remote code execution. The primary defensive takeaway is to ensure affected Festo Automation Suite deployment [truncated]

HIGH CODESYS CVE published 2023-07-11

CVE-2022-47379

CVE-2022-47379 is an authenticated remote memory-corruption issue in multiple CODESYS products used with Festo Automation Suite. CISA’s advisory says the flaw can be used to write data into memory, potentially causing denial of service, memory overwriting, or remote code execution. The safest response is to update Festo Automation Suite and the separately installed CODESYS components to patched versions a [truncated]

MEDIUM CODESYS CVE published 2023-07-11

CVE-2022-47378

CVE-2022-47378 is an authenticated remote denial-of-service vulnerability caused by improper input validation in multiple CODESYS products used in the Festo Automation Suite ecosystem. According to the CISA-republished advisory, an attacker with valid access can craft specific requests that trigger a service disruption. The issue was published on 2026-02-26 and later republished/updated on 2026-03-17 with [truncated]