Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2021-045
Aug. 26, 2025, 12:00 nachm.
The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.
VDE-2022-022
Aug. 26, 2025, 12:00 nachm.
The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.
VDE-2022-036
Juli 28, 2025, 12:00 nachm.
Unauthenticated access to critical webpage functions (e.g. reboot) may cause a denial of service of the device.
VDE-2022-027
Juli 10, 2025, 12:00 nachm.
The Festo controller CECC product family in firmware version 2.4.2.0 is affected by multiple vulnerabilities in the CODESYS V3 runtime.
VDE-2022-020
Juni 23, 2025, 10:00 vorm.
The Festo controller CECC-X-M1 product family in multiple versions are affected by a preauthentication command injection vulnerability. Update A, 2022-07-05 Remediation has been updated. Fixed firmwares are now available.
VDE-2024-055
Juni 5, 2025, 3:32 nachm.
Siemens SIMATIC S7-1200 and S7-1500 CPUs contained in various Festo Didactic products contain a memory protection bypass vulnerability that could allow an attacker to write arbitrary data and code to …
VDE-2023-036
Mai 13, 2025, 12:00 nachm.
A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in …
VDE-2024-059
Dez. 3, 2024, 3:00 nachm.
An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords …