PatchSiren cyber security CVE debrief
CVE-2018-12882 Festo Didactic SE CVE debrief
CVE-2018-12882 is a critical memory-corruption issue in PHP's EXIF handling. The supplied advisory text says exif_read_from_impl in ext/exif/exif.c can trigger a use-after-free in exif_read_from_file because it closes a stream it does not own, and that the vulnerable path is reachable through exif_read_data. In the supplied CISA CSAF mapping, the issue is associated with Festo Didactic SE MES PC systems that used XAMPP/PHP components, with Festo directing users to its Factory Control Panel replacement as the fixed path.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators, OT/ICS administrators, and defenders responsible for systems that include PHP 7.2.x through 7.2.7 with the EXIF extension or a bundled XAMPP/PHP stack.
Technical summary
The vulnerability is a use-after-free in PHP's EXIF implementation. According to the supplied description, exif_read_from_impl closes a stream it is not responsible for closing, which can invalidate memory used later by exif_read_from_file. The reachable entry point is exif_read_data. The supplied CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable, unauthenticated, high-impact exposure if the affected code path is present.
Defensive priority
Immediate / critical
Recommended defensive actions
- Confirm whether any Festo MES PC deployments still use the affected XAMPP/PHP component set.
- Obtain and deploy Festo's current Factory Control Panel version from the vendor support path noted in the advisory.
- Treat PHP 7.2.x through 7.2.7 as vulnerable until the fixed vendor package is verified in place.
- If remediation cannot be completed immediately, isolate affected systems from untrusted network exposure and follow CISA ICS defense-in-depth guidance.
- Validate after change that the vulnerable EXIF code path is no longer present in the deployed software stack.
Evidence notes
The supplied source item is CISA CSAF ICSA-26-027-02, republished on 2026-01-27, and it explicitly maps CVE-2018-12882 to Festo Didactic SE MES PC. The advisory text repeats the PHP EXIF use-after-free description and names exif_read_data as the reachable function. The remediations field states that Festo released Factory Control Panel as a replacement for XAMPP on MES PCs and provides a support contact for the fixed version. No CISA KEV entry is present in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-12882 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-12882
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-12882 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-12882
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.