PatchSiren cyber security CVE debrief
CVE-2018-19935 Festo Didactic SE CVE debrief
CVE-2018-19935 is a high-severity availability issue in PHP’s ext/imap component: an empty string passed as the message argument to imap_mail can lead to a NULL pointer dereference and application crash. In the supplied CISA CSAF context, this appears in the Festo Didactic SE MES PC advisory stream, so operators should treat the issue as relevant wherever that product line depends on the vulnerable PHP stack.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Administrators and OT/industrial IT teams responsible for Festo Didactic SE MES PC deployments, especially systems using PHP 5.x or 7.x before 7.3.0 or related XAMPP/Factory Control Panel components referenced in the advisory.
Technical summary
The advisory describes a remote denial-of-service condition in ext/imap/php_imap.c. If imap_mail is called with an empty string in the message argument, the affected PHP versions can dereference NULL and crash the application. The supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) matches a network-reachable, no-privileges, no-user-interaction availability impact. The source corpus ties the issue to Festo Didactic SE MES PC, while the underlying flaw is in PHP before 7.3.0.
Defensive priority
High for any exposed MES PC or PHP/imap deployment using the affected component, because the bug is remotely triggerable and can cause immediate service interruption.
Recommended defensive actions
- Confirm whether any MES PC environment uses PHP 5.x or 7.x before 7.3.0, or other affected ext/imap deployments.
- Install the supported vendor replacement referenced in the advisory: Factory Control Panel/current Festo-supported release for MES PCs.
- Remove or retire unsupported XAMPP/PHP stacks where possible, especially on systems that must remain available.
- Add server-side input validation so empty message arguments are rejected before imap_mail is invoked.
- Restrict network exposure to MES PC services and apply segmentation and defense-in-depth controls to reduce denial-of-service impact.
- Monitor PHP/application logs for crashes or restarts involving imap-related services and verify recovery procedures and backups.
Evidence notes
The supplied source item is a CISA CSAF republication for Festo Didactic SE MES PC and explicitly describes the PHP ext/imap NULL pointer dereference when imap_mail receives an empty message string. The advisory metadata provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, supporting a remote, no-privileges, high-availability-impact assessment. The corpus also includes an original vendor advisory reference and a remediation entry dated 2023-05-26, while the public CISA republished item used here was published on 2024-02-27 and later modified on 2026-01-27; those dates describe advisory publication history, not the vulnerability’s origin.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-19935 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-19935
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-19935 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-19935
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.