PatchSiren cyber security CVE debrief
CVE-2019-11049 Festo Didactic SE CVE debrief
CVE-2019-11049 is described in the supplied advisory as a PHP memory-corruption issue on Windows that can lead to a double-free when custom headers supplied to mail() are lowercase. In the Festo Didactic SE MES PC advisory bundle, the recommended remediation is to move affected systems to the current Factory Control Panel replacement and obtain it through Festo support.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2019-12-23
- Original CVE updated
- 2026-08-17
- Advisory published
- 2019-12-23
- Advisory updated
- 2026-08-17
Who should care
Administrators, OT/IT support teams, and incident responders responsible for Festo Didactic SE MES PC deployments that may include the affected Windows/PHP/XAMPP stack used by mail() handling.
Technical summary
The source corpus says PHP 7.3.x below 7.3.13 and PHP 7.4.0 on Windows can double-free memory when mail() is called with custom headers supplied in lowercase, due to a mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e. In the republished Festo MES PC advisory, the vendor remediation is to replace XAMPP with Factory Control Panel, which is stated to include fixes for the vulnerabilities.
Defensive priority
Critical
Recommended defensive actions
- Inventory MES PC systems and confirm whether the affected Windows/PHP/XAMPP components are present.
- Apply the vendor-recommended replacement: obtain and deploy the current Factory Control Panel version from Festo technical support ([email protected]).
- Verify the PHP runtime on Windows is at or above the fixed versions referenced in the advisory before returning systems to service.
- After remediation, validate normal application behavior and watch for crashes or other memory-corruption symptoms in the affected stack.
Evidence notes
This debrief is based only on the supplied CISA CSAF republished advisory ICSA-26-027-02 and its cited references. The advisory text ties CVE-2019-11049 to PHP on Windows and states that lowercase custom headers in mail() can trigger a double-free in PHP 7.3.x below 7.3.13 and 7.4.0. The vendor remediation field says Festo Didactic has released Factory Control Panel as a replacement for XAMPP on MES PCs. The supplied timeline shows publication on 2024-02-27 and a later modification/republication on 2026-01-27; the provided data does not include a KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-11049 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-11049
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-11049 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11049
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.