PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-12882 Festo Didactic SE CVE debrief

CVE-2018-12882 is a critical memory-corruption issue in PHP's EXIF handling. The supplied advisory text says exif_read_from_impl in ext/exif/exif.c can trigger a use-after-free in exif_read_from_file because it closes a stream it does not own, and that the vulnerable path is reachable through exif_read_data. In the supplied CISA CSAF mapping, the issue is associated with Festo Didactic SE MES PC systems that used XAMPP/PHP components, with Festo directing users to its Factory Control Panel replacement as the fixed path.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Festo Didactic SE MES PC operators, OT/ICS administrators, and defenders responsible for systems that include PHP 7.2.x through 7.2.7 with the EXIF extension or a bundled XAMPP/PHP stack.

Technical summary

The vulnerability is a use-after-free in PHP's EXIF implementation. According to the supplied description, exif_read_from_impl closes a stream it is not responsible for closing, which can invalidate memory used later by exif_read_from_file. The reachable entry point is exif_read_data. The supplied CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable, unauthenticated, high-impact exposure if the affected code path is present.

Defensive priority

Immediate / critical

Recommended defensive actions

  • Confirm whether any Festo MES PC deployments still use the affected XAMPP/PHP component set.
  • Obtain and deploy Festo's current Factory Control Panel version from the vendor support path noted in the advisory.
  • Treat PHP 7.2.x through 7.2.7 as vulnerable until the fixed vendor package is verified in place.
  • If remediation cannot be completed immediately, isolate affected systems from untrusted network exposure and follow CISA ICS defense-in-depth guidance.
  • Validate after change that the vulnerable EXIF code path is no longer present in the deployed software stack.

Evidence notes

The supplied source item is CISA CSAF ICSA-26-027-02, republished on 2026-01-27, and it explicitly maps CVE-2018-12882 to Festo Didactic SE MES PC. The advisory text repeats the PHP EXIF use-after-free description and names exif_read_data as the reachable function. The remediations field states that Festo released Factory Control Panel as a replacement for XAMPP on MES PCs and provides a support contact for the fixed version. No CISA KEV entry is present in the supplied enrichment.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-12882 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-12882

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-12882 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-12882

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.