<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_festosecokg/10</id>
  <title>Most recent entries from csaf_festosecokg</title>
  <updated>2026-10-05T12:36:10.471279+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202406</id>
    <title>FSA-202406 — Several Codesys Gateway v2 vulnerabilities in Codesys provided by Festo</title>
    <updated>2024-12-03T14:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.</p>
<p>All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:</p>
<p>• CODESYS Gateway Server</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202406"/>
    <published>2024-12-03T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202305</id>
    <title>FSA-202305 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in several products</title>
    <updated>2025-05-13T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202305"/>
    <published>2023-11-28T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202201</id>
    <title>FSA-202201 — Festo: CECC-X-M1 - command injection vulnerabilities</title>
    <updated>2025-06-23T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202201"/>
    <published>2022-07-06T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202203</id>
    <title>FSA-202203 — Festo: Controller CECC-S,LK,D family firmware 2.4.2.0 - multiple vulnerabilities in CODESYS V3 runtime system</title>
    <updated>2025-07-10T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202203"/>
    <published>2022-07-18T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202207</id>
    <title>FSA-202207 — Festo: CPX-CEC-C1 and CPX-CMXX, Missing Authentication for Critical Webpage Function</title>
    <updated>2025-07-28T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202207"/>
    <published>2022-09-20T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202101</id>
    <title>FSA-202101 — Festo: Multiple vulnerabilities in Ethernet/IP Stack of SBRD-Q/SBOC-Q/SBOI-Q</title>
    <updated>2025-08-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202101"/>
    <published>2021-09-22T11:13:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202303</id>
    <title>FSA-202303 — Festo: Vulnerable Siemens TIA-Portal in multiple Festo Didactic products</title>
    <updated>2025-10-01T06:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products.</p>
<p>TP 260 before June 2023 and MES PC based on DELL XE3 contain a vulnerable versions of TIA Portal V15 to V18.</p>
<p>Affected products of TIA Portal contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202303"/>
    <published>2023-10-17T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202301</id>
    <title>FSA-202301 — Festo: Cross-Site-Scripting (XSS) vulnerability in LX-Appliance</title>
    <updated>2025-10-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the "Teacher" role), to craft a malicious course and launch an XSS attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202301"/>
    <published>2023-08-29T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202304</id>
    <title>FSA-202304 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions</title>
    <updated>2025-10-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.</p>
<p>Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today's security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202304"/>
    <published>2023-09-05T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202206</id>
    <title>FSA-202206 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in multiple products</title>
    <updated>2025-10-01T10:50:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &lt; 6.2c and CIROS &lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202206"/>
    <published>2022-12-13T11:50:00+00:00</published>
  </entry>
</feed>
