PatchSiren cyber security CVE debrief
CVE-2023-0662 Festo Didactic SE CVE debrief
CVE-2023-0662 describes a denial-of-service condition in PHP where an excessive number of parts in an HTTP form upload can drive high resource consumption and excessive log generation. The result can be CPU exhaustion or disk-space exhaustion on affected servers; the supplied Festo/CISA advisory frames this issue in an MES PC context and points to a replacement Factory Control Panel release as the vendor remediation path.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Administrators and operators running PHP 8.0.x before 8.0.28, 8.1.x before 8.1.16, or 8.2.x before 8.2.3 should prioritize this, especially if the affected PHP stack is part of a Festo MES PC deployment or another externally reachable service.
Technical summary
The vulnerability is a resource-exhaustion issue in PHP's handling of HTTP form uploads with an excessive number of parts. According to the supplied advisory text, the behavior can cause high CPU usage and excessive log entries, which may lead to denial of service by exhausting CPU resources or disk space. The affected version boundaries listed in the source are PHP 8.0.x before 8.0.28, 8.1.x before 8.1.16, and 8.2.x before 8.2.3.
Defensive priority
High for exposed PHP services and operational environments that depend on the affected PHP versions; prioritize patching or vendor-supported replacement in MES PC deployments.
Recommended defensive actions
- Upgrade PHP to 8.0.28, 8.1.16, or 8.2.3, or later, as applicable to your deployment.
- If you are using the Festo MES PC stack, obtain and deploy the current Factory Control Panel version through Festo support as described in the advisory.
- Review HTTP form upload handling, request limits, and log retention so repeated high-volume uploads cannot exhaust CPU or disk space.
- Monitor affected systems for abnormal log growth, upload anomalies, and resource spikes until remediation is complete.
- Follow CISA ICS recommended practices to reduce exposure and improve resilience around operational systems.
Evidence notes
Primary evidence comes from the supplied CISA CSAF source advisory and the linked official records. The source text states that excessive HTTP form upload parts can cause high resource consumption and excessive log entries, leading to denial of service by exhausting CPU resources or disk space. The advisory metadata identifies the vendor context as Festo Didactic SE / MES PC and lists a vendor remediation dated 2023-05-26, while the CVE and source record were published on 2024-02-27 and later republished/revised on 2026-01-27. No exploit code or unsupported impact claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-0662 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-0662
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-0662 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-0662
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.