PatchSiren cyber security CVE debrief
CVE-2022-27444 Festo Didactic SE CVE debrief
CVE-2022-27444 is a high-severity availability issue referenced in a CISA CSAF advisory for Festo Didactic SE MES PC. The advisory text says MariaDB Server v10.9 and below can hit a segmentation fault in sql/item_subselect.cc, which can disrupt service availability. The supplied advisory corpus also points to Festo’s Factory Control Panel as the replacement path for XAMPP on affected MES PCs.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Organizations operating Festo Didactic MES PC systems, especially those that rely on the affected MariaDB/XAMPP stack or expose the service to network access. OT, training, and lab environments should pay attention because the impact is service outage rather than data compromise.
Technical summary
The source corpus maps CVE-2022-27444 to a denial-of-service condition with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The vulnerability description states that MariaDB Server v10.9 and below can encounter a segmentation fault in sql/item_subselect.cc. In the advisory record, this is associated with Festo Didactic SE MES PC, and the documented remediation is to move to Festo’s Factory Control Panel replacement for XAMPP on MES PCs.
Defensive priority
High for availability-critical environments. The issue is network-reachable, requires no privileges or user interaction per the supplied CVSS vector, and can cause service interruption.
Recommended defensive actions
- Inventory MES PC systems and verify whether they are using the affected MariaDB/XAMPP-based component set.
- Obtain and deploy the current Factory Control Panel version from Festo technical support as directed in the advisory.
- Restrict network exposure to the affected service and limit access to trusted management networks only.
- Monitor for unexpected MariaDB or application crashes, restarts, and service interruptions.
- Validate the remediation during a maintenance window and confirm the replacement component is in place before returning the system to service.
Evidence notes
This debrief is based only on the supplied CISA CSAF advisory record and its listed official references. The advisory text explicitly states the MariaDB Server v10.9-and-below segmentation fault in sql/item_subselect.cc and the remediation note identifies Festo’s Factory Control Panel replacement for XAMPP on MES PCs. The source revision history shows the advisory was initially published on 2024-02-27 and later republished with metadata/template updates.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-27444 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-27444
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-27444 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27444
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.