PatchSiren cyber security CVE debrief
CVE-2021-46663 Festo Didactic SE CVE debrief
CVE-2021-46663 is a medium-severity availability issue involving MariaDB through 10.5.13, where certain SELECT statements can trigger a ha_maria::extra crash. In the supplied CISA CSAF advisory, the issue is associated with Festo Didactic SE MES PC and a vendor replacement path through Factory Control Panel for MES PCs.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators, OT/lab administrators, and anyone maintaining affected systems that may include the MariaDB component referenced in the advisory.
Technical summary
The supplied advisory describes a local crash condition in MariaDB through 10.5.13: certain SELECT statements can cause ha_maria::extra to crash, producing a denial-of-service impact. The advisory context maps the CVE to Festo Didactic SE MES PC and indicates that Festo released Factory Control Panel as a replacement for XAMPP on MES PCs, with fixes included in the current version obtained through vendor technical support. The CVSS vector in the source is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with an availability-only impact and local attack requirements.
Defensive priority
Medium — prioritize if you operate Festo MES PCs or other systems using the affected MariaDB component, especially where local users or services can issue database queries.
Recommended defensive actions
- Inventory MES PC deployments and confirm whether the vendor-recommended Factory Control Panel replacement is installed.
- Obtain the current Factory Control Panel version from Festo technical support and apply the vendor fix path described in the advisory.
- Restrict local database access to trusted users and least-privilege accounts.
- Monitor affected systems for unexpected MariaDB or application crashes and validate recovery procedures.
- Track the CISA CSAF advisory and vendor references for any follow-on updates or clarifications.
Evidence notes
The supplied source is the CISA CSAF advisory ICSA-26-027-02, republished from the Festo advisory context, with publishedAt 2024-02-27 and modifiedAt 2026-01-27. The source description states that MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. The remediation entry says Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and that the current version includes fixes. The source also provides a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and no KEV or ransomware linkage in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-46663 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-46663
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-46663 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46663
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.