PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-3935 Wibu CVE debrief

CVE-2023-3935 is a critical remote code execution vulnerability tied to Festo Automation Suite installations that include CODESYS components. The advisory states that a heap buffer overflow in the Wibu CodeMeter Runtime network service can let an unauthenticated remote attacker gain full host access, so exposed systems should be prioritized for immediate review and patching.

Vendor
Wibu
Product
FESTO
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2023-11-28
Original CVE updated
2023-12-05
Advisory published
2023-11-28
Advisory updated
2023-12-05

Who should care

OT and industrial automation teams using Festo Automation Suite, CODESYS administrators, system integrators, and defenders responsible for Windows or network-exposed engineering workstations and related host systems.

Technical summary

The source advisory describes a heap buffer overflow in the Wibu CodeMeter Runtime network service, affecting versions up to 7.60b. The reported impact is network-reachable, unauthenticated RCE with full host compromise potential, matching CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8). The remediation notes indicate that starting with Festo Automation Suite 2.8.0.138, CODESYS is no longer bundled and must be installed separately, which changes the update path for affected deployments.

Defensive priority

Immediate

Recommended defensive actions

  • Identify all systems running Festo Automation Suite and determine whether they include bundled CODESYS / Wibu CodeMeter Runtime components.
  • Prioritize patching or upgrading to Festo Automation Suite 2.8.0.138 or later where applicable.
  • Install the latest patched CODESYS release from the official CODESYS website and follow vendor update guidance.
  • Verify whether any affected hosts expose the relevant network service beyond trusted management networks and restrict exposure where possible.
  • Monitor vendor and CISA advisories for follow-on updates and confirm remediation across all engineering workstations and related host systems.
  • Reassess asset inventory and dependency management because the bundled component model changes after 2.8.0.138.

Evidence notes

The advisory source is CISA's republication of a Festo SE & Co. KG advisory (ICSA-26-076-01). The source metadata explicitly links CVE-2023-3935 to Festo Automation Suite product entries and states the vulnerable component is Wibu CodeMeter Runtime network service up to version 7.60b. The prompt's vendor field is low-confidence and appears inconsistent with the advisory title; the evidence in the supplied corpus supports Festo/CODESYS rather than the placeholder vendor mapping.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-3935 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-3935

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-3935 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-3935

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2026/fsa-202601.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2025-108

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2595

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.