FSA-202601 PUBLISHED CVSS 5.300000190734863 MEDIUM

Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently. This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite. Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Festo Automation Suite <2.8.0.138
CODESYS Development System 3.5.16.10
CODESYS Development System 3.5.21.20
Festo Automation Suite 2.8.0.138
CODESYS Development System 3.0
Festo Automation Suite 2.8.0.137

Timeline

References

Open in Interactive Console →