PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-27381 Festo Didactic SE CVE debrief

CVE-2022-27381 is a high-severity denial-of-service issue published in a CISA advisory for Festo Didactic SE MES PC. The source description says specially crafted SQL statements can trigger DoS through the MariaDB Server Field::set_default component in version 10.6 and below. The vendor guidance in the advisory points affected users to a fixed Factory Control Panel replacement for XAMPP on MES PCs.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Organizations operating Festo Didactic SE MES PC systems, especially administrators responsible for the bundled database/application stack and any environment where service availability is operationally important.

Technical summary

The advisory assigns CVSS 3.1 7.5 HIGH with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a network-reachable availability impact without privileges or user interaction. The source text attributes the issue to MariaDB Server's Field::set_default component and says specially crafted SQL statements can cause denial of service. The remediation provided in the source is a vendor-supplied Factory Control Panel replacement for XAMPP on MES PCs, which implies the practical fix is to move to the updated replacement package rather than apply a standalone patch described in the corpus.

Defensive priority

High. Prioritize if MES PCs are operationally critical, exposed to untrusted networks, or still using the referenced XAMPP-based stack. Because the issue is a straightforward availability risk with no authentication required, it should be handled ahead of routine maintenance.

Recommended defensive actions

  • Verify whether any Festo MES PC installations still use the vulnerable XAMPP-based components referenced in the advisory.
  • Obtain and deploy the current Factory Control Panel version from Festo technical support, as the source states it includes fixes for the affected vulnerabilities.
  • Restrict network access to any SQL-facing services on affected systems until the fixed replacement is in place.
  • Monitor MES PC availability and logs for unusual SQL activity or repeated service failures that could indicate denial-of-service attempts.
  • Use CISA ICS recommended practices for segmentation, least privilege, and defensive monitoring around affected OT/ICS assets.

Evidence notes

The supplied CISA CSAF source item (ICSA-26-027-02) republished the Festo Didactic SE advisory and lists CVE-2022-27381 with a CVSS 7.5 HIGH availability-only impact. The remediation entry states that Factory Control Panel replaces XAMPP on MES PCs and includes fixes. One important caveat is that the description text references MariaDB Server v10.6 and below, while the advisory metadata names Festo Didactic SE MES PC; this debrief treats that as an advisory-scope linkage from the source corpus rather than an independently verified standalone MariaDB product advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-27381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-27381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-27381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.