PatchSiren cyber security CVE debrief
CVE-2019-11041 Festo Didactic SE CVE debrief
CVE-2019-11041 is an out-of-bounds read in PHP's EXIF parser. When exif_read_data() processes crafted image metadata, affected PHP versions can read past an allocated buffer, which may leak memory contents or crash the process. In the supplied CISA/Festo advisory context, the issue is tied to Festo Didactic SE MES PC, and the documented remediation is a replacement Factory Control Panel for MES PCs that includes fixes for these vulnerabilities.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Administrators and operators of Festo Didactic SE MES PC systems, especially where the vendor-provided Factory Control Panel/XAMPP stack is in use. Security teams supporting OT/ICS environments should also prioritize review if the installation processes untrusted images through PHP EXIF functionality.
Technical summary
The vulnerability affects PHP 7.1.x below 7.1.31, 7.2.x below 7.2.21, and 7.3.x below 7.3.8. During EXIF parsing, a malformed image can cause PHP to read beyond the allocated buffer, leading to information disclosure or a crash. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H, indicating remote reachability but with user interaction required.
Defensive priority
High
Recommended defensive actions
- Identify any Festo MES PC installations and confirm whether they use the vendor-provided Factory Control Panel/XAMPP component set.
- Verify the PHP version in any affected stack and move to a fixed release or the vendor-recommended replacement package.
- Limit exposure to untrusted image files and review any workflow that automatically imports, previews, or processes images through PHP EXIF parsing.
- Monitor affected systems for crashes, abnormal PHP behavior, or memory-disclosure indicators around image ingestion paths.
- Follow CISA ICS recommended practices for segmentation, least privilege, and defensive monitoring on OT/ICS endpoints.
Evidence notes
The source corpus consistently describes a PHP EXIF buffer read-past-allocated-buffer issue that can cause information disclosure or crash. The advisory is a CISA CSAF republication of a Festo notice (tracking ID ICSA-26-027-02 / advisory FSA-202402), and the remediation entry states that Factory Control Panel for MES PCs replaces XAMPP and includes fixes for these vulnerabilities. The provided CVSS vector is AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H. No KEV entry or active-exploitation claim is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-11041 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-11041
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-11041 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11041
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.