PatchSiren cyber security CVE debrief
CVE-2021-21702 Festo Didactic SE CVE debrief
CVE-2021-21702 is a PHP denial-of-service vulnerability that can crash affected PHP processes when the SOAP extension parses malformed XML returned by a malicious SOAP server. In the CISA-republished Festo Didactic SE advisory, the issue is associated with MES PC environments and a replacement Factory Control Panel release. The primary risk is loss of availability, not data theft or code execution.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Organizations running PHP 7.3.x below 7.3.27, 7.4.x below 7.4.15, or 8.0.x below 8.0.2 with the SOAP extension enabled should care, especially if those PHP components are used in Festo Didactic SE MES PC deployments or other internet-reachable or partner-facing integrations. Operations and platform teams responsible for industrial or production-support systems should prioritize this because a crash can interrupt service availability.
Technical summary
The flaw exists in PHP’s SOAP extension: if a SOAP client connects to a malicious or compromised SOAP server that returns malformed XML, PHP may access a null pointer and crash. The supplied advisory describes the impact as a crash, and the CVSS vector reflects a network-reachable availability issue (CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected versions listed in the advisory are PHP 7.3.x before 7.3.27, 7.4.x before 7.4.15, and 8.0.x before 8.0.2.
Defensive priority
High for any exposed or operationally critical PHP SOAP deployment; medium otherwise. Because the impact is service crash and the attack requires only network access to a SOAP interaction path, systems that rely on continuous availability should be patched or replaced promptly.
Recommended defensive actions
- Upgrade PHP to a fixed release at or above 7.3.27, 7.4.15, or 8.0.2, depending on your supported branch.
- If you use Festo Didactic SE MES PC systems, follow the vendor remediation guidance and obtain the current Factory Control Panel release from Festo technical support.
- Inventory where the SOAP extension is enabled and identify any services that contact untrusted or externally reachable SOAP endpoints.
- Reduce exposure to untrusted SOAP servers and place network controls around systems that must communicate with them.
- Monitor affected hosts and application logs for unexpected PHP crashes or repeated service restarts until remediation is complete.
Evidence notes
The source corpus states that a malicious SOAP server can return malformed XML causing PHP to access a null pointer and crash, and lists affected PHP versions. The CISA CSAF republished advisory ties the issue to Festo Didactic SE MES PC and states that Factory Control Panel replaced XAMPP on MES PCs, with fixes included in the current version available through vendor support. The record includes no KEV listing and no ransomware-campaign attribution.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-21702 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-21702
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-21702 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21702
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.