Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-059
Dez. 3, 2024, 3:00 nachm.
An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords …
VDE-2024-055
Juni 5, 2025, 3:32 nachm.
Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to …
VDE-2023-036
Mai 13, 2025, 12:00 nachm.
A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in …
VDE-2023-047
Okt. 1, 2025, 8:00 vorm.
A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products. TP 260 before June 2023 and MES PC based …
VDE-2023-020
Okt. 1, 2025, 12:00 nachm.
Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. The supported features may be covered only partly by the corresponding user documentation. Festo developed the products …
VDE-2023-040
Okt. 1, 2025, 12:00 nachm.
A vulnerability in the Video.js package could allow a user of LX Appliance, with a high privilege account (i.e., with the "Teacher" role), to craft a malicious course and launch …
VDE-2022-038
Okt. 1, 2025, 12:50 nachm.
A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw < 6.2c and CIROS <= 7.0.6 contain a …
VDE-2022-036
Juli 28, 2025, 12:00 nachm.
Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.