PatchSiren cyber security CVE debrief
CVE-2019-11035 Festo Didactic SE CVE debrief
CVE-2019-11035 is a critical memory-safety issue in PHP's EXIF extension. When certain files are processed, exif_iif_add_value can read past an allocated buffer, which may expose memory contents or trigger a crash. In the Festo Didactic SE MES PC advisory, the affected environment is a MES PC platform tied to XAMPP, and Festo says its Factory Control Panel replacement includes fixes.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Administrators and operators responsible for Festo Didactic SE MES PC systems, especially those running XAMPP/PHP components or legacy PHP 7.1/7.2/7.3 releases, should prioritize this.
Technical summary
The flaw is classified as CWE-125 (out-of-bounds read). The supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) indicates a remotely reachable issue with no privileges or user interaction required, and with potential for both information disclosure and service disruption. Affected PHP versions are 7.1.x before 7.1.28, 7.2.x before 7.2.17, and 7.3.x before 7.3.4.
Defensive priority
High. The issue is Critical by CVSS and can expose data or crash affected services. Prioritize any MES PC instance that still depends on the vulnerable PHP EXIF code path. The enrichment supplied here does not mark it as CISA KEV.
Recommended defensive actions
- Verify whether any MES PC deployments still use the affected PHP/XAMPP stack and confirm the exact PHP version in use.
- Move to Festo's current Factory Control Panel offering for MES PCs, as directed in the remediation guidance, by contacting [email protected].
- Upgrade or replace any vulnerable PHP 7.1/7.2/7.3 components so they are no longer within the affected ranges.
- Limit exposure of affected systems to only the networks and users they require, following CISA ICS recommended practices.
- Monitor for unexpected crashes or signs of information exposure in systems processing image or EXIF-bearing files.
Evidence notes
The source item explicitly states that PHP EXIF extension versions 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4 can read past an allocated buffer in exif_iif_add_value, leading to information disclosure or crash. The CSAF metadata ties the advisory to Festo Didactic SE MES PC and records remediation via Factory Control Panel replacement. The provided enrichment says this is not a KEV item.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-11035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-11035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-11035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.