PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-46663 Festo Didactic SE CVE debrief

CVE-2021-46663 is a medium-severity availability issue involving MariaDB through 10.5.13, where certain SELECT statements can trigger a ha_maria::extra crash. In the supplied CISA CSAF advisory, the issue is associated with Festo Didactic SE MES PC and a vendor replacement path through Factory Control Panel for MES PCs.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Festo Didactic SE MES PC operators, OT/lab administrators, and anyone maintaining affected systems that may include the MariaDB component referenced in the advisory.

Technical summary

The supplied advisory describes a local crash condition in MariaDB through 10.5.13: certain SELECT statements can cause ha_maria::extra to crash, producing a denial-of-service impact. The advisory context maps the CVE to Festo Didactic SE MES PC and indicates that Festo released Factory Control Panel as a replacement for XAMPP on MES PCs, with fixes included in the current version obtained through vendor technical support. The CVSS vector in the source is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with an availability-only impact and local attack requirements.

Defensive priority

Medium — prioritize if you operate Festo MES PCs or other systems using the affected MariaDB component, especially where local users or services can issue database queries.

Recommended defensive actions

  • Inventory MES PC deployments and confirm whether the vendor-recommended Factory Control Panel replacement is installed.
  • Obtain the current Factory Control Panel version from Festo technical support and apply the vendor fix path described in the advisory.
  • Restrict local database access to trusted users and least-privilege accounts.
  • Monitor affected systems for unexpected MariaDB or application crashes and validate recovery procedures.
  • Track the CISA CSAF advisory and vendor references for any follow-on updates or clarifications.

Evidence notes

The supplied source is the CISA CSAF advisory ICSA-26-027-02, republished from the Festo advisory context, with publishedAt 2024-02-27 and modifiedAt 2026-01-27. The source description states that MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. The remediation entry says Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and that the current version includes fixes. The source also provides a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and no KEV or ransomware linkage in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-46663 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-46663

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-46663 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46663

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.