PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-11035 Festo Didactic SE CVE debrief

CVE-2019-11035 is a critical memory-safety issue in PHP's EXIF extension. When certain files are processed, exif_iif_add_value can read past an allocated buffer, which may expose memory contents or trigger a crash. In the Festo Didactic SE MES PC advisory, the affected environment is a MES PC platform tied to XAMPP, and Festo says its Factory Control Panel replacement includes fixes.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Administrators and operators responsible for Festo Didactic SE MES PC systems, especially those running XAMPP/PHP components or legacy PHP 7.1/7.2/7.3 releases, should prioritize this.

Technical summary

The flaw is classified as CWE-125 (out-of-bounds read). The supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) indicates a remotely reachable issue with no privileges or user interaction required, and with potential for both information disclosure and service disruption. Affected PHP versions are 7.1.x before 7.1.28, 7.2.x before 7.2.17, and 7.3.x before 7.3.4.

Defensive priority

High. The issue is Critical by CVSS and can expose data or crash affected services. Prioritize any MES PC instance that still depends on the vulnerable PHP EXIF code path. The enrichment supplied here does not mark it as CISA KEV.

Recommended defensive actions

  • Verify whether any MES PC deployments still use the affected PHP/XAMPP stack and confirm the exact PHP version in use.
  • Move to Festo's current Factory Control Panel offering for MES PCs, as directed in the remediation guidance, by contacting [email protected].
  • Upgrade or replace any vulnerable PHP 7.1/7.2/7.3 components so they are no longer within the affected ranges.
  • Limit exposure of affected systems to only the networks and users they require, following CISA ICS recommended practices.
  • Monitor for unexpected crashes or signs of information exposure in systems processing image or EXIF-bearing files.

Evidence notes

The source item explicitly states that PHP EXIF extension versions 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4 can read past an allocated buffer in exif_iif_add_value, leading to information disclosure or crash. The CSAF metadata ties the advisory to Festo Didactic SE MES PC and records remediation via Factory Control Panel replacement. The provided enrichment says this is not a KEV item.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-11035 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-11035

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-11035 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11035

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.