<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_festosecokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:58:33 +0000</lastBuildDate>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
      <pubDate>Thu, 26 Feb 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202406 — Several Codesys Gateway v2 vulnerabilities in Codesys provided by Festo</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202406</link>
      <description>&lt;p&gt;An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.&lt;/p&gt;
&lt;p&gt;All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:&lt;/p&gt;
&lt;p&gt;• CODESYS Gateway Server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.&lt;/p&gt;
&lt;p&gt;All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:&lt;/p&gt;
&lt;p&gt;• CODESYS Gateway Server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202406</guid>
      <pubDate>Tue, 03 Dec 2024 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202405 — Festo: Siemens S7-1500/ET200SP CPU used in Festo Didactic products contains a memory protection bypass vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202405</link>
      <description>&lt;p&gt;Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202405</guid>
      <pubDate>Mon, 09 Sep 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202402 — Several Vulnerabilities in MES PC (Windows 10)</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202402</link>
      <description>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic&amp;#39;s Factory Control Panel application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202402</guid>
      <pubDate>Tue, 27 Feb 2024 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202401 — Festo: Multiple products contain CoDe16 vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202401</link>
      <description>&lt;p&gt;Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202401</guid>
      <pubDate>Tue, 30 Jan 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202305 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in several products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202305</link>
      <description>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202305</guid>
      <pubDate>Tue, 28 Nov 2023 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202303 — Festo: Vulnerable Siemens TIA-Portal in multiple Festo Didactic products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202303</link>
      <description>&lt;p&gt;A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products.&lt;/p&gt;
&lt;p&gt;TP 260 before June 2023 and MES PC based on DELL XE3 contain a vulnerable versions of TIA Portal V15 to V18.&lt;/p&gt;
&lt;p&gt;Affected products of TIA Portal contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products.&lt;/p&gt;
&lt;p&gt;TP 260 before June 2023 and MES PC based on DELL XE3 contain a vulnerable versions of TIA Portal V15 to V18.&lt;/p&gt;
&lt;p&gt;Affected products of TIA Portal contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202303</guid>
      <pubDate>Tue, 17 Oct 2023 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202304 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202304</link>
      <description>&lt;p&gt;Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.&lt;/p&gt;
&lt;p&gt;Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today&amp;#39;s security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.&lt;/p&gt;
&lt;p&gt;Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today&amp;#39;s security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202304</guid>
      <pubDate>Tue, 05 Sep 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202301 — Festo: Cross-Site-Scripting (XSS) vulnerability in LX-Appliance</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202301</link>
      <description>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202301</guid>
      <pubDate>Tue, 29 Aug 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202302</link>
      <description>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202302</guid>
      <pubDate>Mon, 10 Jul 2023 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
