PatchSiren cyber security CVE debrief
CVE-2021-2011 Festo Didactic SE CVE debrief
CVE-2021-2011 is a network-reachable denial-of-service vulnerability in Oracle MySQL Client’s C API. In the supplied CISA CSAF advisory, it is associated with Festo Didactic SE’s MES PC product context, and successful exploitation can cause the client to hang or repeatedly crash. The advisory rates the issue CVSS 5.9 (medium) and notes that exploitation is difficult but does not require authentication.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Operators and maintainers of Festo Didactic SE MES PC deployments, especially where the affected Oracle MySQL Client C API component is present and network-accessible. Asset owners should also care if they rely on bundled or embedded client software that may still be on MySQL Client 5.7.32/8.0.22 or earlier.
Technical summary
The source description states that CVE-2021-2011 affects the MySQL Client product of Oracle MySQL, specifically the C API component, with affected versions 5.7.32 and prior and 8.0.22 and prior. The issue is reachable over the network via multiple protocols and can be triggered by an unauthenticated attacker to produce a hang or a frequently repeatable crash, resulting in complete denial of service. The CVSS vector supplied is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.
Defensive priority
Medium priority. The impact is availability-only but can be disruptive for exposed MES PC installations or any system using the affected client library. Prioritize if the component is network-reachable or if a crash would interrupt industrial or operational workflows.
Recommended defensive actions
- Identify whether MES PC systems include the affected Oracle MySQL Client C API versions (5.7.32 and earlier, or 8.0.22 and earlier).
- Apply the vendor-provided replacement guidance: Festo Didactic states that Factory Control Panel replaces XAMPP on MES PCs and includes fixes for the reported vulnerabilities.
- Obtain the current version through Festo technical support at [email protected], as directed in the advisory.
- Plan for a restart or maintenance window if the vulnerable component must be restarted during remediation.
- Validate post-update stability on representative MES PC systems and watch for hangs or repeated crashes during normal client activity.
- If immediate remediation is not possible, reduce exposure by limiting network access to the affected client systems and the protocols they use.
Evidence notes
This debrief is based on the supplied CISA CSAF source item ICSA-26-027-02 and its referenced Festo advisory materials. The source description ties CVE-2021-2011 to Oracle MySQL Client C API and lists Festo Didactic SE MES PC as the product context. The advisory’s remediation section says Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and that the current version contains fixes. No KEV listing or ransomware-use field was provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-2011 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-2011
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-2011 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-2011
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.