PatchSiren cyber security CVE debrief
CVE-2022-4900 Festo Didactic SE CVE debrief
CVE-2022-4900 is a medium-severity heap buffer overflow in PHP that can be triggered when the PHP_CLI_SERVER_WORKERS environment variable is set to a large value. In the CISA CSAF advisory, the issue is tied to Festo Didactic SE’s MES PC environment and the replacement Factory Control Panel for MES PCs. The published vector indicates availability impact only, with local attack conditions and low complexity.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Operators, administrators, and support teams responsible for Festo Didactic SE MES PC deployments, especially systems using the Factory Control Panel or any bundled PHP/XAMPP-based component referenced in the advisory. Security teams overseeing local administrative access on these systems should also review exposure.
Technical summary
The advisory describes a heap buffer overflow in PHP associated with the PHP_CLI_SERVER_WORKERS environment variable when set to an excessively large value. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which points to a local issue requiring low privileges and resulting in high availability impact. CISA’s CSAF record links the vulnerability to Festo Didactic SE MES PC and states that Factory Control Panel was released as a replacement for XAMPP on MES PCs, with fixes included in the current version obtained through vendor support.
Defensive priority
Medium. The issue is publicly documented and has a vendor remediation path, but it is not listed as KEV and the published scoring indicates local access is needed. Prioritize if you manage affected MES PC systems or any environment where local users or service accounts can influence PHP runtime environment variables.
Recommended defensive actions
- Obtain the current Factory Control Panel version from Festo technical support and deploy the vendor fix on affected MES PCs.
- Review whether any local users, scripts, or service wrappers can set PHP_CLI_SERVER_WORKERS in the affected environment and restrict that control.
- Audit MES PC hosts for the presence of bundled PHP/XAMPP-related components referenced by the advisory and verify they are covered by the vendor replacement.
- Apply standard least-privilege controls so untrusted local accounts cannot influence application startup environment variables.
- Confirm remediation status through change management and document the affected product IDs and replacement version in asset records.
Evidence notes
CISA CSAF advisory ICSA-26-027-02 identifies CVE-2022-4900 for Festo Didactic SE MES PC and cites the issue as a PHP heap buffer overflow caused by setting PHP_CLI_SERVER_WORKERS to a large value. The advisory’s remediation section says Factory Control Panel is the replacement for XAMPP on MES PCs and that the current version includes fixes. The CVSS vector supplied in the advisory is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, supporting a local availability-focused impact assessment. Published date used here is 2024-02-27; later revision entries reflect advisory maintenance and republication, not the original CVE issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-4900 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-4900
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-4900 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-4900
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.