PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-3078 Festo Didactic SE CVE debrief

CVE-2016-3078 is a critical integer-overflow issue in PHP's zip extension, affecting the ZipArchive class methods getFromIndex and getFromName. The supplied CISA CSAF advisory maps the issue to Festo Didactic SE MES PC and states that Festo’s Factory Control Panel replacement for XAMPP on MES PCs includes fixes. Because the flaw is remotely reachable and rated CVSS 9.8 in the source record, affected deployments should treat it as urgent.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Festo Didactic SE MES PC operators and administrators, especially environments that bundle or depend on vulnerable PHP/XAMPP components. OT and industrial-control teams should care most where MES PCs are reachable from other systems or used in production support workflows.

Technical summary

The CVE description reports multiple integer overflows in php_zip.c in PHP before 7.0.6. A crafted call to ZipArchive::getFromIndex or ZipArchive::getFromName can trigger a heap-based buffer overflow and application crash, with possible additional unspecified impact. The supplied advisory assigns CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Defensive priority

Urgent. The issue is remotely reachable, rated critical in the source, and tied in the advisory to a vendor product environment. Prioritize verification of exposure, component replacement, and rollback/containment planning until remediation is complete.

Recommended defensive actions

  • Confirm whether MES PC deployments include a vulnerable PHP zip extension version earlier than 7.0.6.
  • Obtain the current Factory Control Panel release from Festo support, since the advisory says it includes fixes for these vulnerabilities.
  • Review and upgrade any bundled XAMPP/PHP components to versions that include the PHP fix or remove the vulnerable component from the deployment.
  • Limit unnecessary remote access to MES PC management interfaces and isolate affected systems until remediation is verified.

Evidence notes

The supplied CISA CSAF source (ICSA-26-027-02) lists Festo Didactic SE and the product MES PC, repeats the PHP zip extension description for CVE-2016-3078, and provides a remediation note stating that Factory Control Panel for XAMPP on MES PCs includes fixes. The source also includes the CVSS 3.1 vector and official references to the CVE record, NVD detail, vendor advisory, and CISA advisory pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-3078 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-3078

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-3078 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3078

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.