PatchSiren cyber security CVE debrief
CVE-2021-46666 Festo Didactic SE CVE debrief
The supplied government advisory associates CVE-2021-46666 with Festo Didactic SE MES PC and describes an availability-impacting crash condition. The remediation guidance points to a vendor-released replacement for Factory Control Panel on MES PCs. The source corpus is worth reading carefully because the CVE description text also references a MariaDB crash condition, so asset applicability should be verified against the Festo advisory before action is taken.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
OT/ICS defenders, MES PC administrators, and anyone responsible for Festo Didactic SE systems that use the referenced Factory Control Panel/XAMPP stack should review this immediately. Site reliability and maintenance teams should also care because the documented impact is application crash / denial of service, which can disrupt industrial training or production workflows.
Technical summary
Per the supplied CVE description, the issue is a MariaDB crash caused by mishandling a pushdown from a HAVING clause to a WHERE clause, with a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5 MEDIUM). In the supplied advisory metadata, the affected product context is Festo Didactic SE MES PC, and the stated fix is a vendor-provided Factory Control Panel replacement for XAMPP on MES PCs.
Defensive priority
Medium. The CVSS score is moderate, and the primary impact is availability rather than confidentiality or integrity. However, in an OT or MES environment, even a local crash can interrupt operations, so remediation should be prioritized once applicability is confirmed.
Recommended defensive actions
- Confirm whether your MES PC deployment matches the Festo advisory context and uses the affected Factory Control Panel/XAMPP package.
- Obtain the current Factory Control Panel release from Festo technical support and deploy the vendor-fixed version.
- Plan the update in a maintenance window and validate the replacement package in a test environment before production rollout.
- Monitor MES PC service stability and crash logs until remediation is complete.
- Because the supplied corpus mixes a MariaDB crash description with Festo MES PC advisory metadata, verify exposure against the official Festo and CISA advisory references before making changes.
Evidence notes
Source item published 2024-02-27 and republished 2026-01-27 in the CISA CSAF corpus. The supplied metadata ties the advisory to Festo Didactic SE MES PC and recommends replacing Factory Control Panel, while the CVE description text itself states a MariaDB crash before 10.6.2 caused by HAVING-to-WHERE pushdown mishandling. That mismatch is present in the supplied corpus, so this debrief avoids assuming a broader exploitability or product impact beyond the cited references.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-46666 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-46666
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-46666 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46666
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.