<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_festosecokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:40:14 +0000</lastBuildDate>
    <item>
      <title>FSA-202406 — Several Codesys Gateway v2 vulnerabilities in Codesys provided by Festo</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202406</link>
      <description>&lt;p&gt;An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.&lt;/p&gt;
&lt;p&gt;All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:&lt;/p&gt;
&lt;p&gt;• CODESYS Gateway Server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.&lt;/p&gt;
&lt;p&gt;All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:&lt;/p&gt;
&lt;p&gt;• CODESYS Gateway Server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202406</guid>
      <pubDate>Tue, 03 Dec 2024 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202305 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in several products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202305</link>
      <description>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202305</guid>
      <pubDate>Tue, 28 Nov 2023 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202201 — Festo: CECC-X-M1 - command injection vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202201</link>
      <description>&lt;p&gt;The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability.
Update A, 2022-07-05
Remediation has been updated. Fixed firmwares are now available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202201</guid>
      <pubDate>Wed, 06 Jul 2022 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202203 — Festo: Controller CECC-S,LK,D family firmware 2.4.2.0 - multiple vulnerabilities in CODESYS V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202203</link>
      <description>&lt;p&gt;The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202203</guid>
      <pubDate>Mon, 18 Jul 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202207 — Festo: CPX-CEC-C1 and CPX-CMXX, Missing Authentication for Critical Webpage Function</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202207</link>
      <description>&lt;p&gt;Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202207</guid>
      <pubDate>Tue, 20 Sep 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202101 — Festo: Multiple vulnerabilities in Ethernet/IP Stack of SBRD-Q/SBOC-Q/SBOI-Q</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202101</link>
      <description>&lt;p&gt;The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202101</guid>
      <pubDate>Wed, 22 Sep 2021 11:13:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202303 — Festo: Vulnerable Siemens TIA-Portal in multiple Festo Didactic products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202303</link>
      <description>&lt;p&gt;A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products.&lt;/p&gt;
&lt;p&gt;TP 260 before June 2023 and MES PC based on DELL XE3 contain a vulnerable versions of TIA Portal V15 to V18.&lt;/p&gt;
&lt;p&gt;Affected products of TIA Portal contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products.&lt;/p&gt;
&lt;p&gt;TP 260 before June 2023 and MES PC based on DELL XE3 contain a vulnerable versions of TIA Portal V15 to V18.&lt;/p&gt;
&lt;p&gt;Affected products of TIA Portal contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202303</guid>
      <pubDate>Tue, 17 Oct 2023 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202301 — Festo: Cross-Site-Scripting (XSS) vulnerability in LX-Appliance</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202301</link>
      <description>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the &amp;#34;Teacher&amp;#34; role), to craft a malicious course and launch an XSS attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202301</guid>
      <pubDate>Tue, 29 Aug 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202304 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202304</link>
      <description>&lt;p&gt;Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.&lt;/p&gt;
&lt;p&gt;Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today&amp;#39;s security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. 
The supported features may be covered only partly by the corresponding user documentation.&lt;/p&gt;
&lt;p&gt;Festo developed the products according to the respective state of the art. As a result, the protocols used no longer fully meet today&amp;#39;s security requirements. 
The products are designed and developed for use in sealed-off (industrial) networks.
If the network is not adequately sealed off, unauthorized access to the product can cause damage or malfunctions, particularly Denial of Service (DoS) or loss of integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202304</guid>
      <pubDate>Tue, 05 Sep 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>FSA-202206 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202206</link>
      <description>&lt;p&gt;A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &amp;lt; 6.2c and CIROS &amp;lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw &amp;lt; 6.2c and CIROS &amp;lt;= 7.0.6 contain a vulnerable version of WIBU-SYSTEMS CodeMeter Runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202206</guid>
      <pubDate>Tue, 13 Dec 2022 11:50:00 +0000</pubDate>
    </item>
  </channel>
</rss>
