PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-46667 Festo Didactic SE CVE debrief

CVE-2021-46667 describes an integer overflow in MariaDB's sql_lex.cc code path before 10.6.5 that can cause an application crash. In the supplied CISA CSAF advisory corpus, the issue is associated with Festo Didactic SE MES PC and a vendor replacement path through Factory Control Panel. The published CVSS vector is local and availability-only, so the main risk is loss of service rather than data compromise.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Operators of Festo Didactic SE MES PC deployments, administrators running affected MariaDB versions before 10.6.5, and teams responsible for production systems where a local crash would interrupt operations.

Technical summary

The source advisory links CVE-2021-46667 to an integer overflow in MariaDB's sql_lex.cc, with impact limited to an application crash. The supplied CVSS 3.1 vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a locally reachable issue requiring low privileges and resulting in high availability impact. The CISA CSAF metadata maps the advisory to Festo Didactic SE MES PC and notes a replacement product path via Factory Control Panel.

Defensive priority

Medium priority: address during normal maintenance, but move faster if the vulnerable component is present on production MES PCs or any local user can interact with it.

Recommended defensive actions

  • Confirm whether any deployed systems include MariaDB versions earlier than 10.6.5 or the Festo Didactic SE MES PC configuration named in the advisory.
  • Apply the vendor-provided replacement: obtain the current Factory Control Panel from Festo technical support, as stated in the CSAF remediation.
  • If you manage MariaDB directly in another context, upgrade to MariaDB 10.6.5 or later where applicable.
  • Limit local access and privileges on affected hosts to reduce exposure to the locally exploitable crash condition.
  • Monitor affected systems for unexpected MariaDB or application crashes and verify recovery procedures for production MES environments.

Evidence notes

The source corpus is a CISA CSAF advisory for "Festo Didactic SE MES PC" (ICSA-26-027-02) published on 2024-02-27, with later revision history including a 2026-01-27 republication entry. The advisory description explicitly states: "MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash." The remediation section states that Festo Didactic has released Factory Control Panel as a replacement for XAMPP on its MES PCs and directs users to obtain the current version from Festo support. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The 2026-01-27 timestamp in the corpus is a republication/revision date, not the original vulnerability date.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-46667 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-46667

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-46667 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46667

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.