PatchSiren cyber security CVE debrief
CVE-2018-17082 Festo Didactic SE CVE debrief
CVE-2018-17082 is a cross-site scripting (XSS) issue in PHP's Apache2 component when handling the body of a Transfer-Encoding: chunked request. The source advisory says the bucket brigade is mishandled in php_handler in sapi/apache2handler/sapi_apache2.c. In the supplied advisory context, the issue is associated with Festo Didactic SE MES PC systems that used the affected PHP stack. The CVSS v3.0 vector provided is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1, Medium), which means network reachability and user interaction both matter. The CVE/public-advisory date is 2024-02-27; the later 2026-01-27 source republication is a repository timeline event, not the original vulnerability date.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
MES PC administrators and operators, especially where the system exposes PHP/Apache2 web functionality or uses a bundled XAMPP/PHP stack; also security teams responsible for upgrading embedded or industrial workstation software.
Technical summary
The flaw affects PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10. According to the advisory, Apache2 SAPI request-body handling can leave attacker-controlled data in a state that enables XSS when a chunked request is processed and later rendered in a browser context. The issue is in the PHP Apache2 handler path rather than in Apache HTTP Server itself.
Defensive priority
Medium: patch promptly on any exposed or operator-facing deployment. The impact is limited, but the flaw is network-reachable, requires user interaction, and can affect browser sessions.
Recommended defensive actions
- Upgrade PHP to a fixed release: 5.6.38 or later, 7.0.32 or later, 7.1.22 or later, or 7.2.10 or later, or use a vendor-supplied build that includes the fix.
- For Festo Didactic MES PC deployments, follow the vendor remediation and move to the current Factory Control Panel replacement; obtain the current version through Festo technical support.
- Treat any internet-facing or broadly reachable PHP/Apache2 management interface as higher priority until the fixed build is in place.
- Review exposed web pages that reflect request content and reduce access to affected interfaces until the upgrade is complete.
Evidence notes
The source corpus explicitly identifies the vulnerable PHP versions, the Apache2 SAPI code path, and the XSS impact. It also provides the CVSS vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N and a vendor remediation note stating that Factory Control Panel replaces XAMPP on MES PCs. Timing should be read from the supplied CVE publishedAt date (2024-02-27), not the later source republication date (2026-01-27).
Sources and references
Verified primary and authoritative sources
-
CVE-2018-17082 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-17082
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-17082 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-17082
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.