PatchSiren cyber security CVE debrief
CVE-2021-21703 Festo Didactic SE CVE debrief
CVE-2021-21703 is a high-severity local privilege-escalation issue tied in CISA’s advisory to Festo Didactic SE MES PC deployments that use vulnerable PHP-FPM versions. In the affected PHP ranges, a lower-privileged worker can alter shared memory in a way that can trigger invalid reads and writes in the root-owned master process, creating a path to root compromise on the host.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Organizations running Festo Didactic SE MES PC systems, especially if they still depend on PHP-FPM/XAMPP-style deployments with a root master daemon and non-root worker processes. Linux administrators and OT/industrial operators should prioritize this if any local user access exists on the affected system.
Technical summary
The advisory describes a PHP-FPM memory corruption condition in PHP 7.3.x through 7.3.31, 7.4.x below 7.4.25, and 8.0.x below 8.0.12. The risk depends on a common FPM privilege separation pattern: the main daemon runs as root while child workers run as lower-privileged users. Under those conditions, a worker can access and write to shared memory associated with the main process, potentially causing the root process to perform invalid memory reads and writes and enabling local privilege escalation.
Defensive priority
High
Recommended defensive actions
- Move to the vendor-recommended replacement: Festo Didactic states that Factory Control Panel replaces XAMPP on MES PCs and includes fixes for these vulnerabilities.
- Verify whether any MES PC deployment still uses affected PHP-FPM versions or a root-owned FPM master with lower-privileged workers.
- Apply the current fixed Factory Control Panel version through Festo Didactic technical support as directed in the advisory.
- Limit local shell access and reduce the number of users who can interact with the affected host until remediation is complete.
- Review the system for privilege-separation assumptions in PHP-FPM deployments and treat root-owned service processes as high-value targets.
Evidence notes
This debrief is based on the CISA CSAF republication for Festo Didactic SE MES PC and its referenced vendor materials. The source text explicitly states the affected PHP version ranges, the root/master and lower-privileged worker condition, the local privilege-escalation impact, and the vendor remediation that replaces XAMPP with Factory Control Panel. No exploit code or unsupported attribution was used.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-21703 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-21703
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-21703 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21703
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.