PatchSiren cyber security CVE debrief
CVE-2021-35604 Festo Didactic SE CVE debrief
CISA’s republished advisory for Festo Didactic SE MES PC identifies CVE-2021-35604 as an Oracle MySQL InnoDB issue with availability and limited integrity impact. The advisory says affected versions include MySQL 5.7.35 and prior, and 8.0.26 and prior, and that successful attacks can cause a hang or repeatable crash as well as unauthorized insert, update, or delete activity on some accessible data. Festo’s remediation path points to a current Factory Control Panel release that includes fixes.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators, OT/ICS administrators, and support teams responsible for systems that include the affected MySQL/InnoDB component or the Factory Control Panel/XAMPP replacement path.
Technical summary
The CISA CSAF advisory for Festo Didactic SE MES PC maps CVE-2021-35604 to Oracle MySQL Server’s InnoDB component. The advisory states that MySQL 5.7.35 and earlier and 8.0.26 and earlier are affected. Successful exploitation by a high-privilege network attacker over multiple protocols can lead to a hang or frequently repeatable crash (complete DoS) and limited unauthorized insert, update, or delete access to accessible data. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H.
Defensive priority
Medium. The attack requires high privileges but is network reachable and can affect availability and integrity, which is significant for MES/OT environments.
Recommended defensive actions
- Identify whether any Festo MES PC deployments still include the vulnerable MySQL/InnoDB versions noted in the advisory.
- Obtain and deploy the current Factory Control Panel version referenced by Festo support.
- Confirm asset inventory and configuration for MES PCs, including any XAMPP or embedded MySQL components.
- Restrict administrative access and network paths to the affected service while remediation is scheduled.
- Validate after update that the MySQL service no longer matches the affected version ranges.
Evidence notes
CISA’s advisory ICSA-26-027-02, republished from the Festo advisory lineage, lists CVE-2021-35604 for Festo Didactic SE MES PC and describes Oracle MySQL Server/InnoDB impact, affected versions, the CVSS vector, and the vendor remediation path via Factory Control Panel. The source revision history shows the initial advisory date of 2024-02-27 and a later CISA republication on 2026-01-27; the remediation entry is dated 2023-05-26.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-35604 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-35604
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-35604 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-35604
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.