PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-27445 Festo Didactic SE CVE debrief

CVE-2022-27445 is a high-severity denial-of-service issue with a CVSS 3.1 score of 7.5. The source advisory ties the CVE to Festo Didactic SE MES PC, while the CVE description says MariaDB Server v10.9 and below can hit a segmentation fault in sql/sql_window.cc. The main operational concern is loss of availability: affected systems may crash or become unavailable if exposed to the vulnerable condition.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

OT and industrial control system teams using Festo Didactic SE MES PC, especially administrators responsible for patching, replacement planning, uptime, and crash monitoring. Security teams should also review whether any deployed software stack includes the vulnerable MariaDB component referenced by the CVE description.

Technical summary

The source corpus associates CVE-2022-27445 with a MariaDB segmentation fault in sql/sql_window.cc and provides a CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a remotely reachable availability impact. In the CSAF advisory, the affected product is Festo Didactic SE MES PC, and the listed vendor remediation is to replace XAMPP with Factory Control Panel obtained from Festo technical support. The advisory materials do not provide exploit details; the impact described is service interruption through crashing or segmentation fault behavior.

Defensive priority

High for exposed MES PC deployments. The issue is not listed as a KEV entry, but the availability impact is severe and the advisory includes a vendor replacement path, so affected environments should treat remediation as a near-term priority.

Recommended defensive actions

  • Inventory Festo Didactic SE MES PC deployments and confirm whether they match the advisory scope.
  • Obtain the current Factory Control Panel from Festo technical support and plan replacement of XAMPP as directed by the vendor remediation.
  • Validate whether any installed MariaDB component matches the vulnerable versions described in the CVE record.
  • Monitor affected systems for crashes, segmentation faults, or unexpected service interruptions.
  • Apply ICS defense-in-depth and hardening guidance from CISA recommended practices while remediation is underway.

Evidence notes

This debrief is based only on the supplied CISA CSAF source item, its embedded revision history, and the official references listed in the corpus. The source item was initially published on 2024-02-27 and republished by CISA on 2026-01-27. The corpus does not mark the CVE as a KEV item and does not provide evidence of ransomware use. The advisory references include the CVE record, NVD, Festo PSIRT, CERT@VDE, and CISA advisory pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-27445 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-27445

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-27445 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27445

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.