PatchSiren cyber security CVE debrief
CVE-2016-3078 Festo Didactic SE CVE debrief
CVE-2016-3078 is a critical integer-overflow issue in PHP's zip extension, affecting the ZipArchive class methods getFromIndex and getFromName. The supplied CISA CSAF advisory maps the issue to Festo Didactic SE MES PC and states that Festo’s Factory Control Panel replacement for XAMPP on MES PCs includes fixes. Because the flaw is remotely reachable and rated CVSS 9.8 in the source record, affected deployments should treat it as urgent.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators and administrators, especially environments that bundle or depend on vulnerable PHP/XAMPP components. OT and industrial-control teams should care most where MES PCs are reachable from other systems or used in production support workflows.
Technical summary
The CVE description reports multiple integer overflows in php_zip.c in PHP before 7.0.6. A crafted call to ZipArchive::getFromIndex or ZipArchive::getFromName can trigger a heap-based buffer overflow and application crash, with possible additional unspecified impact. The supplied advisory assigns CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Defensive priority
Urgent. The issue is remotely reachable, rated critical in the source, and tied in the advisory to a vendor product environment. Prioritize verification of exposure, component replacement, and rollback/containment planning until remediation is complete.
Recommended defensive actions
- Confirm whether MES PC deployments include a vulnerable PHP zip extension version earlier than 7.0.6.
- Obtain the current Factory Control Panel release from Festo support, since the advisory says it includes fixes for these vulnerabilities.
- Review and upgrade any bundled XAMPP/PHP components to versions that include the PHP fix or remove the vulnerable component from the deployment.
- Limit unnecessary remote access to MES PC management interfaces and isolate affected systems until remediation is verified.
Evidence notes
The supplied CISA CSAF source (ICSA-26-027-02) lists Festo Didactic SE and the product MES PC, repeats the PHP zip extension description for CVE-2016-3078, and provides a remediation note stating that Factory Control Panel for XAMPP on MES PCs includes fixes. The source also includes the CVSS 3.1 vector and official references to the CVE record, NVD detail, vendor advisory, and CISA advisory pages.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-3078 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-3078
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-3078 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3078
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.