Title:
FSA-202208 - Security Advisory - Unsafe default Codesys configuration
Subtitle:
Multiple Festo products contain an unsafe default Codesys configuration
Description:

The products are shipped with an unsafe configuration of the integrated CODESYS Runtime environment. In this case no default password is set to the CODESYS PLC and therefore access without authentication is possible.

 

With a successful established connection to the CODESYS Runtime the PLC-Browser commands are available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop the application and reboot the device.

Document type:
Security Advisory
Title Version

CSAF edition of FSA-202208

PFD edition of FSA-202208