PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-21703 Festo Didactic SE CVE debrief

CVE-2021-21703 is a high-severity local privilege-escalation issue tied in CISA’s advisory to Festo Didactic SE MES PC deployments that use vulnerable PHP-FPM versions. In the affected PHP ranges, a lower-privileged worker can alter shared memory in a way that can trigger invalid reads and writes in the root-owned master process, creating a path to root compromise on the host.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Organizations running Festo Didactic SE MES PC systems, especially if they still depend on PHP-FPM/XAMPP-style deployments with a root master daemon and non-root worker processes. Linux administrators and OT/industrial operators should prioritize this if any local user access exists on the affected system.

Technical summary

The advisory describes a PHP-FPM memory corruption condition in PHP 7.3.x through 7.3.31, 7.4.x below 7.4.25, and 8.0.x below 8.0.12. The risk depends on a common FPM privilege separation pattern: the main daemon runs as root while child workers run as lower-privileged users. Under those conditions, a worker can access and write to shared memory associated with the main process, potentially causing the root process to perform invalid memory reads and writes and enabling local privilege escalation.

Defensive priority

High

Recommended defensive actions

  • Move to the vendor-recommended replacement: Festo Didactic states that Factory Control Panel replaces XAMPP on MES PCs and includes fixes for these vulnerabilities.
  • Verify whether any MES PC deployment still uses affected PHP-FPM versions or a root-owned FPM master with lower-privileged workers.
  • Apply the current fixed Factory Control Panel version through Festo Didactic technical support as directed in the advisory.
  • Limit local shell access and reduce the number of users who can interact with the affected host until remediation is complete.
  • Review the system for privilege-separation assumptions in PHP-FPM deployments and treat root-owned service processes as high-value targets.

Evidence notes

This debrief is based on the CISA CSAF republication for Festo Didactic SE MES PC and its referenced vendor materials. The source text explicitly states the affected PHP version ranges, the root/master and lower-privileged worker condition, the local privilege-escalation impact, and the vendor remediation that replaces XAMPP with Factory Control Panel. No exploit code or unsupported attribution was used.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-21703 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-21703

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-21703 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21703

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.