PatchSiren cyber security CVE debrief
CVE-2022-27387 Festo Didactic SE CVE debrief
CVE-2022-27387 is a high-severity MariaDB issue affecting Festo Didactic SE MES PC environments that rely on MariaDB Server v10.7 and below. The advisory describes a global buffer overflow in decimal_bin_size that can be triggered by specially crafted SQL statements, with the primary security consequence being denial of service. CISA published the advisory on 2024-02-27 and later republished it on 2026-01-27 from the Festo vendor advisory lineage. Festo’s remediation notes point to Factory Control Panel as the replacement for XAMPP on affected MES PCs, with fixes included in the current version provided through vendor support.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC operators, industrial/OT administrators, and support teams responsible for systems that include MariaDB or legacy XAMPP-based components. Security teams should also care if MES PCs are exposed to untrusted network users or if SQL input paths can be reached by applications or integrations.
Technical summary
The advisory text states that MariaDB Server v10.7 and below contains a global buffer overflow in decimal_bin_size. The attack vector in the supplied CVSS vector is network-based, requires no privileges, and no user interaction, with availability impact rated high and confidentiality/integrity impact rated none. The source corpus ties the issue to Festo Didactic SE MES PC and recommends moving to Factory Control Panel, which is described as including fixes for these vulnerabilities.
Defensive priority
High. The issue is remotely reachable according to the supplied CVSS vector, and the documented impact is high availability loss. For MES/OT environments, even a denial-of-service condition can disrupt production or training operations, so remediation should be prioritized wherever affected MariaDB components remain in use.
Recommended defensive actions
- Confirm whether any Festo Didactic SE MES PC systems still use MariaDB Server v10.7 or below, or legacy XAMPP components referenced by the vendor remediation.
- Obtain and deploy the current Factory Control Panel version from Festo support, as the advisory states it includes fixes for these vulnerabilities.
- Validate the affected MES PC build and component inventory before rollout so the replacement path matches the vendor-supported remediation.
- Restrict access to database interfaces and SQL entry points to trusted systems only, especially on OT networks where the attack surface should be minimized.
- Test the vendor update in a maintenance window and verify that the vulnerable component is no longer present after remediation.
- Monitor for service instability or unexpected restarts during and after update deployment, since the remediation notes indicate a restart is required for the vulnerable component.
Evidence notes
The supplied CISA CSAF advisory (ICSA-26-027-02) identifies the product as Festo Didactic SE MES PC and repeats the vendor description that MariaDB Server v10.7 and below is vulnerable to a global buffer overflow in decimal_bin_size via specially crafted SQL statements. The source metadata lists the CVE publication date as 2024-02-27 and the latest modification as 2026-01-27. The remediation entry dated 2023-05-26 states that Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and that the current version includes fixes. No KEV entry is present in the supplied enrichment fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-27387 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-27387
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-27387 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27387
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.