PatchSiren cyber security CVE debrief
CVE-2021-2194 Festo Didactic SE CVE debrief
CVE-2021-2194 is an availability issue described in the supplied corpus as affecting Oracle MySQL Server InnoDB, with a network-accessible high-privilege attack path that can cause a hang or repeatable crash. The advisory context is published under Festo Didactic SE MES PC, and the source remediation points to a Factory Control Panel replacement path that includes fixes.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
OT/ICS operators, MES PC administrators, and anyone managing affected MySQL Server instances or privileged access in the Festo advisory context should pay attention, especially where service availability is operationally important.
Technical summary
The supplied advisory text describes a vulnerability in Oracle MySQL Server's InnoDB component affecting 5.7.33 and prior and 8.0.23 and prior. The attack requires network access and high privileges, uses no UI, and can result in a hang or frequently repeatable crash of the MySQL Server, which maps to denial of service only in the provided CVSS vector and description.
Defensive priority
Medium
Recommended defensive actions
- Inventory any affected MySQL Server deployments in the MES PC environment and confirm whether versions 5.7.33 or earlier, or 8.0.23 or earlier, are present.
- Follow the vendor remediation path in the source corpus: obtain the current Factory Control Panel from Festo technical support because it is described as including fixes.
- Restrict privileged database access to trusted administrative hosts and limit unnecessary network reachability to the service.
- Enable monitoring for MySQL hangs, crashes, and unexpected restarts so availability problems are detected quickly.
- Validate backups, recovery procedures, and service restart controls so an availability event does not interrupt operations for long.
Evidence notes
This debrief uses only the supplied CISA CSAF source item ICSA-26-027-02, its linked references, and the provided timeline fields. The corpus associates the advisory with Festo Didactic SE MES PC while the vulnerability description itself identifies Oracle MySQL Server InnoDB; the summary above stays within those source statements and does not add unsupported details.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-2194 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-2194
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-2194 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-2194
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.