<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_festosecokg/10</id>
  <title>Most recent entries from csaf_festosecokg</title>
  <updated>2026-10-02T08:01:07.250644+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202601</id>
    <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
    <updated>2026-02-26T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202601"/>
    <published>2026-02-26T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202302</id>
    <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
    <updated>2026-02-02T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>FactoryViews bundles many third-party applications which are used in background processes to provide the software's features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.</p>
<p>FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.</p>
<p>At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202302"/>
    <published>2023-07-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202402</id>
    <title>FSA-202402 — Several Vulnerabilities in MES PC (Windows 10)</title>
    <updated>2025-12-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.</p>
<p>MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202402"/>
    <published>2024-02-27T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202405</id>
    <title>FSA-202405 — Festo: Siemens S7-1500/ET200SP CPU used in Festo Didactic products contains a memory protection bypass vulnerability</title>
    <updated>2025-11-05T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202405"/>
    <published>2024-09-09T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202401</id>
    <title>FSA-202401 — Festo: Multiple products contain CoDe16 vulnerability</title>
    <updated>2025-11-04T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202401"/>
    <published>2024-01-30T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202202</id>
    <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
    <updated>2025-11-03T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202202"/>
    <published>2022-07-18T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202209</id>
    <title>FSA-202209 — Festo: Incomplete documentation of remote accessible functions and protocols in Festo products</title>
    <updated>2025-11-03T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incomplete Festo product documentation of remote accessible functions and their required IP ports. Depending on the product a description of the supported features can be found in the product documentation to some extent.
Update A, 2022-12-13
Added affected device "Bus module CPX-E-PN, 4080497"</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202209"/>
    <published>2022-11-29T11:49:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202208</id>
    <title>FSA-202208 — Festo: Multiple Festo products contain an unsafe default Codesys configuration</title>
    <updated>2025-10-28T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.</p>
<p>With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202208"/>
    <published>2022-11-29T11:41:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202206</id>
    <title>FSA-202206 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in multiple products</title>
    <updated>2025-10-01T10:50:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &lt; 6.2c and CIROS &lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202206"/>
    <published>2022-12-13T11:50:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202304</id>
    <title>FSA-202304 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions</title>
    <updated>2025-10-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.</p>
<p>Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today's security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202304"/>
    <published>2023-09-05T10:00:00+00:00</published>
  </entry>
</feed>
