PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-35604 Festo Didactic SE CVE debrief

CISA’s republished advisory for Festo Didactic SE MES PC identifies CVE-2021-35604 as an Oracle MySQL InnoDB issue with availability and limited integrity impact. The advisory says affected versions include MySQL 5.7.35 and prior, and 8.0.26 and prior, and that successful attacks can cause a hang or repeatable crash as well as unauthorized insert, update, or delete activity on some accessible data. Festo’s remediation path points to a current Factory Control Panel release that includes fixes.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Festo Didactic SE MES PC operators, OT/ICS administrators, and support teams responsible for systems that include the affected MySQL/InnoDB component or the Factory Control Panel/XAMPP replacement path.

Technical summary

The CISA CSAF advisory for Festo Didactic SE MES PC maps CVE-2021-35604 to Oracle MySQL Server’s InnoDB component. The advisory states that MySQL 5.7.35 and earlier and 8.0.26 and earlier are affected. Successful exploitation by a high-privilege network attacker over multiple protocols can lead to a hang or frequently repeatable crash (complete DoS) and limited unauthorized insert, update, or delete access to accessible data. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H.

Defensive priority

Medium. The attack requires high privileges but is network reachable and can affect availability and integrity, which is significant for MES/OT environments.

Recommended defensive actions

  • Identify whether any Festo MES PC deployments still include the vulnerable MySQL/InnoDB versions noted in the advisory.
  • Obtain and deploy the current Factory Control Panel version referenced by Festo support.
  • Confirm asset inventory and configuration for MES PCs, including any XAMPP or embedded MySQL components.
  • Restrict administrative access and network paths to the affected service while remediation is scheduled.
  • Validate after update that the MySQL service no longer matches the affected version ranges.

Evidence notes

CISA’s advisory ICSA-26-027-02, republished from the Festo advisory lineage, lists CVE-2021-35604 for Festo Didactic SE MES PC and describes Oracle MySQL Server/InnoDB impact, affected versions, the CVSS vector, and the vendor remediation path via Factory Control Panel. The source revision history shows the initial advisory date of 2024-02-27 and a later CISA republication on 2026-01-27; the remediation entry is dated 2023-05-26.

Official resources

Publicly disclosed in a CISA CSAF advisory on 2024-02-27 and republished by CISA on 2026-01-27 from the Festo advisory lineage.