PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-46668 Festo Didactic SE CVE debrief

CVE-2021-46668 is an availability-impacting MariaDB issue that can cause an application crash when certain long SELECT DISTINCT statements interact badly with storage-engine limits for temporary data structures. In the CISA CSAF advisory corpus, the issue is mapped to Festo Didactic SE’s MES PC environment, and Festo’s remediation points to replacing XAMPP with Factory Control Panel on MES PCs. The published CVSS vector rates the issue as local, low-privilege, and high-availability impact only.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Operators and administrators of Festo Didactic SE MES PCs, teams maintaining MES deployments that include MariaDB/XAMPP components, and OT/ICS support staff responsible for patching or replacing the affected software stack.

Technical summary

The supplied advisory text describes a MariaDB through 10.5.9 condition where certain long SELECT DISTINCT statements can improperly interact with storage-engine resource limits for temporary data structures, resulting in an application crash. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local attack path with no confidentiality or integrity impact and a high availability impact. The CSAF record associates the issue with Festo Didactic SE MES PC and references a vendor remediation that replaces XAMPP with Factory Control Panel.

Defensive priority

Medium. The issue is a denial-of-service condition rather than a code-execution flaw, but it can still disrupt MES availability. Prioritize it for systems where downtime affects training, production support, or operational continuity.

Recommended defensive actions

  • Obtain and deploy the current Factory Control Panel version from Festo technical support, as cited in the remediation guidance.
  • Replace or remove the vulnerable XAMPP-based MES PC component set where applicable, following the vendor’s replacement guidance.
  • Inventory MES PC installations to confirm whether the affected MariaDB/XAMPP stack is present.
  • Schedule updates during maintenance windows and verify that the replacement does not reintroduce the vulnerable component.
  • Review and follow CISA ICS recommended practices for defense-in-depth and operational continuity.

Evidence notes

This debrief is based only on the supplied CSAF corpus and the provided official reference links. The vulnerability text states that MariaDB through 10.5.9 may crash via certain long SELECT DISTINCT statements that interact with storage-engine limits for temporary data structures. The CSAF metadata maps the CVE to Festo Didactic SE, product MES PC, and the remediation notes say Festo Didactic released Factory Control Panel as a replacement for XAMPP on its MES PCs. The CVE published date used here is 2024-02-27; later CSAF revision/republication dates are not treated as the issue date.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-46668 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-46668

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-46668 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-46668

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.