PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-17082 Festo Didactic SE CVE debrief

CVE-2018-17082 is a cross-site scripting (XSS) issue in PHP's Apache2 component when handling the body of a Transfer-Encoding: chunked request. The source advisory says the bucket brigade is mishandled in php_handler in sapi/apache2handler/sapi_apache2.c. In the supplied advisory context, the issue is associated with Festo Didactic SE MES PC systems that used the affected PHP stack. The CVSS v3.0 vector provided is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1, Medium), which means network reachability and user interaction both matter. The CVE/public-advisory date is 2024-02-27; the later 2026-01-27 source republication is a repository timeline event, not the original vulnerability date.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

MES PC administrators and operators, especially where the system exposes PHP/Apache2 web functionality or uses a bundled XAMPP/PHP stack; also security teams responsible for upgrading embedded or industrial workstation software.

Technical summary

The flaw affects PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10. According to the advisory, Apache2 SAPI request-body handling can leave attacker-controlled data in a state that enables XSS when a chunked request is processed and later rendered in a browser context. The issue is in the PHP Apache2 handler path rather than in Apache HTTP Server itself.

Defensive priority

Medium: patch promptly on any exposed or operator-facing deployment. The impact is limited, but the flaw is network-reachable, requires user interaction, and can affect browser sessions.

Recommended defensive actions

  • Upgrade PHP to a fixed release: 5.6.38 or later, 7.0.32 or later, 7.1.22 or later, or 7.2.10 or later, or use a vendor-supplied build that includes the fix.
  • For Festo Didactic MES PC deployments, follow the vendor remediation and move to the current Factory Control Panel replacement; obtain the current version through Festo technical support.
  • Treat any internet-facing or broadly reachable PHP/Apache2 management interface as higher priority until the fixed build is in place.
  • Review exposed web pages that reflect request content and reduce access to affected interfaces until the upgrade is complete.

Evidence notes

The source corpus explicitly identifies the vulnerable PHP versions, the Apache2 SAPI code path, and the XSS impact. It also provides the CVSS vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N and a vendor remediation note stating that Factory Control Panel replaces XAMPP on MES PCs. Timing should be read from the supplied CVE publishedAt date (2024-02-27), not the later source republication date (2026-01-27).

Sources and references

Verified primary and authoritative sources

  • CVE-2018-17082 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-17082

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-17082 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-17082

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.