PatchSiren cyber security CVE debrief
CVE-2021-35604 Festo Didactic SE CVE debrief
CISA’s republished advisory for Festo Didactic SE MES PC identifies CVE-2021-35604 as an Oracle MySQL InnoDB issue with availability and limited integrity impact. The advisory says affected versions include MySQL 5.7.35 and prior, and 8.0.26 and prior, and that successful attacks can cause a hang or repeatable crash as well as unauthorized insert, update, or delete activity on some accessible data. Festo’s remediation path points to a current Factory Control Panel release that includes fixes.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators, OT/ICS administrators, and support teams responsible for systems that include the affected MySQL/InnoDB component or the Factory Control Panel/XAMPP replacement path.
Technical summary
The CISA CSAF advisory for Festo Didactic SE MES PC maps CVE-2021-35604 to Oracle MySQL Server’s InnoDB component. The advisory states that MySQL 5.7.35 and earlier and 8.0.26 and earlier are affected. Successful exploitation by a high-privilege network attacker over multiple protocols can lead to a hang or frequently repeatable crash (complete DoS) and limited unauthorized insert, update, or delete access to accessible data. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H.
Defensive priority
Medium. The attack requires high privileges but is network reachable and can affect availability and integrity, which is significant for MES/OT environments.
Recommended defensive actions
- Identify whether any Festo MES PC deployments still include the vulnerable MySQL/InnoDB versions noted in the advisory.
- Obtain and deploy the current Factory Control Panel version referenced by Festo support.
- Confirm asset inventory and configuration for MES PCs, including any XAMPP or embedded MySQL components.
- Restrict administrative access and network paths to the affected service while remediation is scheduled.
- Validate after update that the MySQL service no longer matches the affected version ranges.
Evidence notes
CISA’s advisory ICSA-26-027-02, republished from the Festo advisory lineage, lists CVE-2021-35604 for Festo Didactic SE MES PC and describes Oracle MySQL Server/InnoDB impact, affected versions, the CVSS vector, and the vendor remediation path via Factory Control Panel. The source revision history shows the initial advisory date of 2024-02-27 and a later CISA republication on 2026-01-27; the remediation entry is dated 2023-05-26.
Official resources
-
CVE-2021-35604 CVE record
CVE.org
-
CVE-2021-35604 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Publicly disclosed in a CISA CSAF advisory on 2024-02-27 and republished by CISA on 2026-01-27 from the Festo advisory lineage.