PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-27376 Festo Didactic SE CVE debrief

CVE-2022-27376 is a high-severity use-after-free in MariaDB's Item_args::walk_arg that can be triggered by specially crafted SQL statements. In the supplied CISA/Festo advisory context, it is tied to Festo Didactic SE MES PC deployments that used XAMPP; Festo's remediation is to move to Factory Control Panel, which the vendor says includes fixes.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Festo MES PC operators, industrial/lab administrators, and defenders responsible for hosts that still use XAMPP or other bundled MariaDB components.

Technical summary

The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates unauthenticated network exploitation with availability impact only. The vulnerable code path is Item_args::walk_arg, where crafted SQL can trigger a use-after-free and lead to service disruption or crash. The supplied corpus does not include proof-of-concept details, exploitation telemetry, or KEV inclusion.

Defensive priority

High for any exposed MES PC instance that still uses the vulnerable stack; prioritize inventory and vendor-supplied replacement because exploitation requires no privileges or user interaction. Since it is not listed in the supplied KEV data, treat it as a fix-now operational risk rather than a known-exploited item.

Recommended defensive actions

  • Inventory all Festo Didactic MES PC deployments and identify whether XAMPP or the affected MariaDB component is present.
  • Install the vendor-recommended Factory Control Panel version obtained through Festo technical support, per the advisory, and verify the replacement is current.
  • Reduce network exposure for affected hosts until remediation is complete, and monitor for anomalous SQL activity or service instability.
  • After remediation, confirm the vulnerable component version is no longer present and document the update for asset records.

Evidence notes

Source evidence comes from CISA's republished CSAF advisory for Festo Didactic SE MES PC (ICSA-26-027-02 / CVE-2022-27376), which cites the MariaDB use-after-free and lists a vendor remediation replacing XAMPP with Factory Control Panel. The corpus shows publication on 2024-02-27 and does not show KEV inclusion.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-27376 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-27376

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-27376 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27376

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.