PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-9021 Festo Didactic SE CVE debrief

CVE-2019-9021 is a critical memory-disclosure flaw in PHP’s PHAR file-reading logic. The issue can cause a heap-based buffer over-read while parsing a file name, allowing an attacker to read data past the intended boundary. In the supplied CISA CSAF advisory, the issue is mapped to Festo Didactic SE’s MES PC environment, with Festo directing customers to a replacement Factory Control Panel release that includes fixes.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

OT/ICS administrators, MES PC operators, and security teams responsible for Festo Didactic SE deployments should review this immediately, especially where bundled PHP/PHAR components or XAMPP-derived stacks may still be present.

Technical summary

The underlying vulnerability is a heap-based buffer over-read in PHP PHAR reading functions, specifically related to phar_detect_phar_fname_ext in ext/phar/phar.c. When parsing a file name, affected PHP versions can read beyond the actual data into allocated or unallocated memory, which may expose process memory contents. The CISA CSAF source associates the issue with Festo Didactic SE MES PC and states that a current Factory Control Panel release replaces XAMPP on those systems and includes fixes.

Defensive priority

Immediate

Recommended defensive actions

  • Identify all Festo MES PC deployments and confirm whether the affected PHP/PHAR component path is present.
  • Obtain and deploy the current Factory Control Panel version from Festo technical support, as directed in the advisory.
  • Replace or upgrade any exposed XAMPP-based or PHP-based components according to Festo guidance.
  • Verify remediation using the official CISA and vendor advisories plus internal asset inventory records.
  • Apply standard ICS hardening practices such as segmentation, least privilege, and monitoring around affected systems.

Evidence notes

The supplied source item is CISA CSAF advisory ICSA-26-027-02 for Festo Didactic SE MES PC. Its description matches the PHP PHAR heap-based buffer over-read language in the CVE record, and its remediation section states that Festo released Factory Control Panel as a replacement for XAMPP on MES PCs and that customers should contact technical support for the fixed version. The advisory metadata shows initial publication on 2024-02-27 and a later republication/revision history entry on 2026-01-27; those are advisory dates, not the original vulnerability date.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-9021 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-9021

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-9021 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-9021

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.