Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2025-108
Feb. 26, 2026, 9:00 AM
Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled …
VDE-2024-059
Dec. 3, 2024, 3:00 PM
An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords …
VDE-2024-055
Nov. 5, 2025, 9:00 AM
Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to …
VDE-2023-065
Dec. 8, 2025, 8:00 AM
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time …
VDE-2023-063
Nov. 4, 2025, 12:00 PM
Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.
VDE-2023-036
May 13, 2025, 12:00 PM
A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in …
VDE-2023-047
Oct. 1, 2025, 8:00 AM
A vulnerability was reported in Siemens TIA Portal. TIA Portal is part of the installation packages of several Festo Didactic products. TP 260 before June 2023 and MES PC based …
VDE-2023-020
Oct. 1, 2025, 12:00 PM
Incomplete user documentation of undocumented, authenticated test mode and further remote accessible functions. The supported features may be covered only partly by the corresponding user documentation. Festo developed the products …