PatchSiren cyber security CVE debrief
CVE-2022-32082 Festo Didactic SE CVE debrief
CVE-2022-32082 is a high-severity denial-of-service issue described in a CISA advisory for Festo Didactic SE MES PC. The source notes an assertion failure in MariaDB v10.5 through v10.7, which can affect availability rather than confidentiality or integrity. Festo’s remediation guidance points operators to a replacement Factory Control Panel package for MES PCs.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Operators of Festo Didactic SE MES PC systems, OT/ICS administrators, and support teams responsible for the bundled MariaDB/XAMPP environment should care most.
Technical summary
The advisory content links CVE-2022-32082 to an assertion failure at `table->get_ref_count() == 0` in `dict0dict.cc` affecting MariaDB v10.5 to v10.7. The published CVSS vector is `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`, indicating a network-reachable condition with no required privileges or user interaction and a primary impact of denial of service via availability loss. The source remediation states that Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs.
Defensive priority
High
Recommended defensive actions
- Identify MES PC deployments that use the affected MariaDB/XAMPP-based stack or the older Factory Control Panel components mentioned in the advisory.
- Obtain and deploy the current Factory Control Panel package from Festo Didactic technical support as directed in the remediation guidance.
- Plan updates during a maintenance window and verify service restart requirements for the vulnerable component.
- Confirm the fixed package is installed on all applicable MES PCs and document version status.
- Monitor affected systems for unexpected application crashes or restart loops until remediation is complete.
Evidence notes
The source advisory for Festo Didactic SE MES PC states: 'MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.' The remediation field says Festo Didactic released Factory Control Panel as a replacement for XAMPP on MES PCs and directs customers to technical support for the current version. The advisory metadata includes CVSS 3.1 vector `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`, consistent with a network-reachable availability impact. Published date in the source corpus is 2024-02-27, with a later CISA republication on 2026-01-27.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-32082 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-32082
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-32082 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-32082
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.