PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-7059 Festo Didactic SE CVE debrief

CVE-2020-7059 describes a PHP fgetss() buffer over-read that can lead to information disclosure or a crash. In the CISA advisory for Festo Didactic SE MES PC, the vendor points users to a replacement Factory Control Panel for XAMPP on MES PCs and says the current version includes fixes.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Organizations running Festo Didactic SE MES PC deployments, especially administrators responsible for XAMPP/Factory Control Panel software and any embedded PHP components. This is most important where the affected system is exposed to untrusted input or supports operational workflows that cannot tolerate crashes or data leakage.

Technical summary

According to the source advisory, using fgetss() with tag stripping in PHP 7.2.x before 7.2.27, 7.3.x before 7.3.14, and 7.4.x before 7.4.2 can cause the function to read past the allocated buffer. The stated outcomes are information disclosure or a crash. The CISA CSAF advisory maps this issue to Festo Didactic SE MES PC and references a vendor-provided replacement package as the remediation path.

Defensive priority

Critical: prioritize validation and update planning immediately for any MES PC environment that may include the affected PHP versions or the vendor-referenced XAMPP-based software stack.

Recommended defensive actions

  • Contact Festo technical support and obtain the current Factory Control Panel version referenced by the vendor as containing fixes for these vulnerabilities.
  • Verify whether any MES PC deployment uses PHP versions earlier than 7.2.27, 7.3.14, or 7.4.2 and update to a fixed release where applicable.
  • Review the CISA ICS recommended practices and defense-in-depth guidance to reduce exposure while remediation is underway.
  • Confirm the updated software is deployed and functioning as expected, then document the software version and remediation status for the affected MES PC assets.

Evidence notes

The debrief is based on the supplied CISA CSAF source item for ICSA-26-027-02, which states the buffer over-read condition, affected PHP version ranges, impact, and vendor remediation language. The source references the official CVE record, CISA advisory, Festo PSIRT/vendor advisory pages, and CISA ICS defensive guidance. No exploit details are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2020-7059 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2020-7059

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2020-7059 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2020-7059

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.