PatchSiren cyber security CVE debrief
CVE-2022-27381 Festo Didactic SE CVE debrief
CVE-2022-27381 is a high-severity denial-of-service issue published in a CISA advisory for Festo Didactic SE MES PC. The source description says specially crafted SQL statements can trigger DoS through the MariaDB Server Field::set_default component in version 10.6 and below. The vendor guidance in the advisory points affected users to a fixed Factory Control Panel replacement for XAMPP on MES PCs.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Organizations operating Festo Didactic SE MES PC systems, especially administrators responsible for the bundled database/application stack and any environment where service availability is operationally important.
Technical summary
The advisory assigns CVSS 3.1 7.5 HIGH with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a network-reachable availability impact without privileges or user interaction. The source text attributes the issue to MariaDB Server's Field::set_default component and says specially crafted SQL statements can cause denial of service. The remediation provided in the source is a vendor-supplied Factory Control Panel replacement for XAMPP on MES PCs, which implies the practical fix is to move to the updated replacement package rather than apply a standalone patch described in the corpus.
Defensive priority
High. Prioritize if MES PCs are operationally critical, exposed to untrusted networks, or still using the referenced XAMPP-based stack. Because the issue is a straightforward availability risk with no authentication required, it should be handled ahead of routine maintenance.
Recommended defensive actions
- Verify whether any Festo MES PC installations still use the vulnerable XAMPP-based components referenced in the advisory.
- Obtain and deploy the current Factory Control Panel version from Festo technical support, as the source states it includes fixes for the affected vulnerabilities.
- Restrict network access to any SQL-facing services on affected systems until the fixed replacement is in place.
- Monitor MES PC availability and logs for unusual SQL activity or repeated service failures that could indicate denial-of-service attempts.
- Use CISA ICS recommended practices for segmentation, least privilege, and defensive monitoring around affected OT/ICS assets.
Evidence notes
The supplied CISA CSAF source item (ICSA-26-027-02) republished the Festo Didactic SE advisory and lists CVE-2022-27381 with a CVSS 7.5 HIGH availability-only impact. The remediation entry states that Factory Control Panel replaces XAMPP on MES PCs and includes fixes. One important caveat is that the description text references MariaDB Server v10.6 and below, while the advisory metadata names Festo Didactic SE MES PC; this debrief treats that as an advisory-scope linkage from the source corpus rather than an independently verified standalone MariaDB product advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-27381 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-27381
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-27381 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27381
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.