PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-0662 Festo Didactic SE CVE debrief

CVE-2023-0662 describes a denial-of-service condition in PHP where an excessive number of parts in an HTTP form upload can drive high resource consumption and excessive log generation. The result can be CPU exhaustion or disk-space exhaustion on affected servers; the supplied Festo/CISA advisory frames this issue in an MES PC context and points to a replacement Factory Control Panel release as the vendor remediation path.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Administrators and operators running PHP 8.0.x before 8.0.28, 8.1.x before 8.1.16, or 8.2.x before 8.2.3 should prioritize this, especially if the affected PHP stack is part of a Festo MES PC deployment or another externally reachable service.

Technical summary

The vulnerability is a resource-exhaustion issue in PHP's handling of HTTP form uploads with an excessive number of parts. According to the supplied advisory text, the behavior can cause high CPU usage and excessive log entries, which may lead to denial of service by exhausting CPU resources or disk space. The affected version boundaries listed in the source are PHP 8.0.x before 8.0.28, 8.1.x before 8.1.16, and 8.2.x before 8.2.3.

Defensive priority

High for exposed PHP services and operational environments that depend on the affected PHP versions; prioritize patching or vendor-supported replacement in MES PC deployments.

Recommended defensive actions

  • Upgrade PHP to 8.0.28, 8.1.16, or 8.2.3, or later, as applicable to your deployment.
  • If you are using the Festo MES PC stack, obtain and deploy the current Factory Control Panel version through Festo support as described in the advisory.
  • Review HTTP form upload handling, request limits, and log retention so repeated high-volume uploads cannot exhaust CPU or disk space.
  • Monitor affected systems for abnormal log growth, upload anomalies, and resource spikes until remediation is complete.
  • Follow CISA ICS recommended practices to reduce exposure and improve resilience around operational systems.

Evidence notes

Primary evidence comes from the supplied CISA CSAF source advisory and the linked official records. The source text states that excessive HTTP form upload parts can cause high resource consumption and excessive log entries, leading to denial of service by exhausting CPU resources or disk space. The advisory metadata identifies the vendor context as Festo Didactic SE / MES PC and lists a vendor remediation dated 2023-05-26, while the CVE and source record were published on 2024-02-27 and later republished/revised on 2026-01-27. No exploit code or unsupported impact claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-0662 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-0662

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-0662 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-0662

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.