PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-46666 Festo Didactic SE CVE debrief

The supplied government advisory associates CVE-2021-46666 with Festo Didactic SE MES PC and describes an availability-impacting crash condition. The remediation guidance points to a vendor-released replacement for Factory Control Panel on MES PCs. The source corpus is worth reading carefully because the CVE description text also references a MariaDB crash condition, so asset applicability should be verified against the Festo advisory before action is taken.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

OT/ICS defenders, MES PC administrators, and anyone responsible for Festo Didactic SE systems that use the referenced Factory Control Panel/XAMPP stack should review this immediately. Site reliability and maintenance teams should also care because the documented impact is application crash / denial of service, which can disrupt industrial training or production workflows.

Technical summary

Per the supplied CVE description, the issue is a MariaDB crash caused by mishandling a pushdown from a HAVING clause to a WHERE clause, with a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5 MEDIUM). In the supplied advisory metadata, the affected product context is Festo Didactic SE MES PC, and the stated fix is a vendor-provided Factory Control Panel replacement for XAMPP on MES PCs.

Defensive priority

Medium. The CVSS score is moderate, and the primary impact is availability rather than confidentiality or integrity. However, in an OT or MES environment, even a local crash can interrupt operations, so remediation should be prioritized once applicability is confirmed.

Recommended defensive actions

  • Confirm whether your MES PC deployment matches the Festo advisory context and uses the affected Factory Control Panel/XAMPP package.
  • Obtain the current Factory Control Panel release from Festo technical support and deploy the vendor-fixed version.
  • Plan the update in a maintenance window and validate the replacement package in a test environment before production rollout.
  • Monitor MES PC service stability and crash logs until remediation is complete.
  • Because the supplied corpus mixes a MariaDB crash description with Festo MES PC advisory metadata, verify exposure against the official Festo and CISA advisory references before making changes.

Evidence notes

Source item published 2024-02-27 and republished 2026-01-27 in the CISA CSAF corpus. The supplied metadata ties the advisory to Festo Didactic SE MES PC and recommends replacing Factory Control Panel, while the CVE description text itself states a MariaDB crash before 10.6.2 caused by HAVING-to-WHERE pushdown mishandling. That mismatch is present in the supplied corpus, so this debrief avoids assuming a broader exploitability or product impact beyond the cited references.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-46666 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-46666

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-46666 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46666

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.