PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-32082 Festo Didactic SE CVE debrief

CVE-2022-32082 is a high-severity denial-of-service issue described in a CISA advisory for Festo Didactic SE MES PC. The source notes an assertion failure in MariaDB v10.5 through v10.7, which can affect availability rather than confidentiality or integrity. Festo’s remediation guidance points operators to a replacement Factory Control Panel package for MES PCs.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Operators of Festo Didactic SE MES PC systems, OT/ICS administrators, and support teams responsible for the bundled MariaDB/XAMPP environment should care most.

Technical summary

The advisory content links CVE-2022-32082 to an assertion failure at `table->get_ref_count() == 0` in `dict0dict.cc` affecting MariaDB v10.5 to v10.7. The published CVSS vector is `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`, indicating a network-reachable condition with no required privileges or user interaction and a primary impact of denial of service via availability loss. The source remediation states that Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs.

Defensive priority

High

Recommended defensive actions

  • Identify MES PC deployments that use the affected MariaDB/XAMPP-based stack or the older Factory Control Panel components mentioned in the advisory.
  • Obtain and deploy the current Factory Control Panel package from Festo Didactic technical support as directed in the remediation guidance.
  • Plan updates during a maintenance window and verify service restart requirements for the vulnerable component.
  • Confirm the fixed package is installed on all applicable MES PCs and document version status.
  • Monitor affected systems for unexpected application crashes or restart loops until remediation is complete.

Evidence notes

The source advisory for Festo Didactic SE MES PC states: 'MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.' The remediation field says Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and directs customers to technical support for the current version. The advisory metadata includes CVSS 3.1 vector `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`, consistent with a network-reachable availability impact. Published date in the source corpus is 2024-02-27, with a later CISA republication on 2026-01-27.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-32082 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-32082

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-32082 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-32082

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.