PatchSiren cyber security CVE debrief
CVE-2022-27446 Festo Didactic SE CVE debrief
CVE-2022-27446 is a high-severity availability issue in the supplied advisory corpus. The published CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which means the primary concern is denial of service rather than data theft or tampering. The source corpus associates the CVE with a CISA CSAF advisory for Festo Didactic SE MES PC, while the advisory description states that MariaDB Server v10.9 and below can hit a segmentation fault in sql/item_cmpfunc.h. For defenders, the practical takeaway is that systems using the affected MES PC stack should be identified and updated or replaced promptly. The advisory remediation points to Factory Control Panel as the replacement for XAMPP on MES PCs, obtained through Festo technical support. No KEV listing or exploit campaign is provided in the supplied corpus.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Festo Didactic SE MES PC owners, industrial training/lab operators, OT/ICS administrators, and any team running the affected XAMPP/MariaDB-based MES PC stack.
Technical summary
The source corpus describes a segmentation fault affecting MariaDB Server v10.9 and below, with the advisory context mapped to Festo Didactic SE MES PC. The stated impact is availability-only, consistent with the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The corpus does not provide exploit details beyond the service-crash condition. Remediation guidance in the advisory points to replacing XAMPP with Factory Control Panel on MES PCs and obtaining the current version through Festo support.
Defensive priority
High. Treat as a prompt availability-risk remediation for any exposed or production-dependent MES PC deployment, especially where service interruption would affect lab, training, or industrial operations.
Recommended defensive actions
- Inventory MES PCs and confirm whether the affected MariaDB/XAMPP stack is present.
- Obtain the current Factory Control Panel replacement from Festo Didactic support and deploy the vendor-recommended fix.
- Validate service restoration and confirm that the vulnerable component is no longer in use after remediation.
- Reduce network exposure and apply ICS defense-in-depth controls while remediation is pending, especially on systems reachable from broader networks.
Evidence notes
The supplied corpus contains a context mismatch: the advisory metadata identifies Festo Didactic SE MES PC as the affected product context, while the advisory description names MariaDB Server v10.9 and below and cites a segmentation fault in sql/item_cmpfunc.h. This debrief preserves both statements without inferring a product relationship beyond what the corpus explicitly provides. Timing is based on the supplied CVE published date of 2024-02-27 and modified date of 2026-01-27.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-27446 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-27446
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-27446 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27446
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.