<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_festosecokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:17:07 +0000</lastBuildDate>
    <item>
      <title>FSA-202101 — Festo: Multiple vulnerabilities in Ethernet/IP Stack of SBRD-Q/SBOC-Q/SBOI-Q</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202101</link>
      <description>&lt;p&gt;The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202101</guid>
      <pubDate>Wed, 22 Sep 2021 11:13:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202201 — Festo: CECC-X-M1 - command injection vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202201</link>
      <description>&lt;p&gt;The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202201</guid>
      <pubDate>Wed, 06 Jul 2022 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202202</link>
      <description>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202202</guid>
      <pubDate>Mon, 18 Jul 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202203 — Festo: Controller CECC-S,LK,D family firmware 2.4.2.0 - multiple vulnerabilities in CODESYS V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202203</link>
      <description>&lt;p&gt;The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202203</guid>
      <pubDate>Mon, 18 Jul 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202207 — Festo: CPX-CEC-C1 and CPX-CMXX, Missing Authentication for Critical Webpage Function</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202207</link>
      <description>&lt;p&gt;Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202207</guid>
      <pubDate>Tue, 20 Sep 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202208 — Festo: Multiple Festo products contain an unsafe default Codesys configuration</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202208</link>
      <description>&lt;p&gt;The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.&lt;/p&gt;
&lt;p&gt;With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.&lt;/p&gt;
&lt;p&gt;With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202208</guid>
      <pubDate>Tue, 29 Nov 2022 11:41:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202209 — Festo: Incomplete documentation of remote accessible functions and protocols in Festo products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202209</link>
      <description>&lt;p&gt;Incomplete Festo product documentation of remote accessible functions and their required IP ports. Depending on the product a description of the supported features can be found in the product documentation to some extent.
Update A, 2022-12-13
Added affected device &amp;#34;Bus module CPX-E-PN, 4080497&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incomplete Festo product documentation of remote accessible functions and their required IP ports. Depending on the product a description of the supported features can be found in the product documentation to some extent.
Update A, 2022-12-13
Added affected device &amp;#34;Bus module CPX-E-PN, 4080497&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202209</guid>
      <pubDate>Tue, 29 Nov 2022 11:49:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202206 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202206</link>
      <description>&lt;p&gt;A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &amp;lt; 6.2c and CIROS &amp;lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &amp;lt; 6.2c and CIROS &amp;lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202206</guid>
      <pubDate>Tue, 13 Dec 2022 11:50:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202302</link>
      <description>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202302</guid>
      <pubDate>Mon, 10 Jul 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202301 — Festo: Cross-Site-Scripting (XSS) vulnerability in LX-Appliance</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202301</link>
      <description>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202301</guid>
      <pubDate>Tue, 29 Aug 2023 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
