These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CISA’s CSAF advisory ICSA-26-027-02 ties CVE-2022-27449 to Festo Didactic SE MES PC and describes a segmentation fault in MariaDB Server v10.9 and below. The impact is availability-only (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), so defenders should treat it as a network-reachable denial-of-service risk rather than a code-execution issue. Festo’s stated remediation is to move MES PCs to the current F [truncated]
CVE-2022-27448 is a high-severity availability issue associated in the supplied advisory corpus with Festo Didactic SE MES PC. The advisory text links the problem to an assertion failure in MariaDB Server v10.9 and below at /row/row0mysql.cc, which can cause the affected service to stop functioning. Festo’s remediation in the corpus points customers to a replacement Factory Control Panel release that incl [truncated]
CVE-2022-27447 is a high-severity use-after-free in MariaDB Server v10.9 and below, surfaced in a CISA CSAF advisory for Festo Didactic SE MES PC. The advisory’s remediation path points operators to Festo’s current Factory Control Panel release and associated support guidance, indicating the issue affects the bundled software stack used on those systems.
CVE-2022-27446 is a high-severity availability issue in the supplied advisory corpus. The published CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which means the primary concern is denial of service rather than data theft or tampering. The source corpus associates the CVE with a CISA CSAF advisory for Festo Didactic SE MES PC, while the advisory description states that MariaDB Server v10.9 and b [truncated]
CVE-2022-27445 is a high-severity denial-of-service issue with a CVSS 3.1 score of 7.5. The source advisory ties the CVE to Festo Didactic SE MES PC, while the CVE description says MariaDB Server v10.9 and below can hit a segmentation fault in sql/sql_window.cc. The main operational concern is loss of availability: affected systems may crash or become unavailable if exposed to the vulnerable condition.
CVE-2022-27444 is a high-severity availability issue referenced in a CISA CSAF advisory for Festo Didactic SE MES PC. The advisory text says MariaDB Server v10.9 and below can hit a segmentation fault in sql/item_subselect.cc, which can disrupt service availability. The supplied advisory corpus also points to Festo’s Factory Control Panel as the replacement path for XAMPP on affected MES PCs.
CVE-2022-27387 is a high-severity MariaDB issue affecting Festo Didactic SE MES PC environments that rely on MariaDB Server v10.7 and below. The advisory describes a global buffer overflow in decimal_bin_size that can be triggered by specially crafted SQL statements, with the primary security consequence being denial of service. CISA published the advisory on 2024-02-27 and later republished it on 2026-01 [truncated]
CVE-2022-27386 is presented in the supplied advisory corpus as a high-severity availability issue (CVSS 7.5) linked to Festo Didactic SE MES PC, with the vulnerability text stating that MariaDB Server v10.7 and below can hit a segmentation fault in sql/sql_class.cc. The available material focuses on defensive remediation: Festo Didactic states that Factory Control Panel replaced XAMPP on MES PCs and that [truncated]
CVE-2022-27385 is a high-severity availability issue described in the Festo Didactic SE MES PC advisory corpus. The source text ties the problem to the MariaDB-related component "Used_tables_and_const_cache::used_tables_and_const_cache_join" and states that specially crafted SQL statements can cause denial of service. The advisory’s remediation says Festo Didactic released Factory Control Panel as a repla [truncated]
CVE-2022-27384 is a network-reachable denial-of-service issue described in the Festo Didactic SE MES PC advisory material. The source description attributes the problem to MariaDB Server's Item_subselect::init_expr_cache_tracker path in v10.6 and below, where specially crafted SQL statements can disrupt availability. The CISA CSAF remediation guidance points affected MES PC users toward Festo's Factory Co [truncated]
According to the supplied advisory record, CVE-2022-27383 involves a use-after-free in MariaDB Server v10.6 and below, specifically in my_strcasecmp_8bit. The issue can be triggered with specially crafted SQL statements and is scored CVSS 7.5 (HIGH) because it can cause high availability impact without requiring privileges or user interaction. The source record is tied to a Festo Didactic SE MES PC adviso [truncated]
CVE-2022-27382 is a high-severity availability issue referenced in Festo Didactic SE MES PC advisory material. The source description says MariaDB Server v10.7 and below can hit a segmentation fault in Item_field::used_tables/update_depend_map_for_order, which can lead to service disruption rather than data theft or integrity loss. For MES PC operators, the practical concern is unplanned downtime in syste [truncated]
CVE-2022-27381 is a high-severity denial-of-service issue published in a CISA advisory for Festo Didactic SE MES PC. The source description says specially crafted SQL statements can trigger DoS through the MariaDB Server Field::set_default component in version 10.6 and below. The vendor guidance in the advisory points affected users to a fixed Factory Control Panel replacement for XAMPP on MES PCs.
CVE-2022-27380 is a high-severity denial-of-service issue referenced in the Festo Didactic SE MES PC advisory materials published through CISA. The source description says specially crafted SQL statements can trigger a DoS in a MariaDB component, and the remediation guidance points affected users to Factory Control Panel as the replacement for XAMPP. Because the supplied corpus mixes a Festo product advis [truncated]
CVE-2022-27379 is a denial-of-service vulnerability affecting the MariaDB Server component Arg_comparator::compare_real_fixed, described in the CISA CSAF advisory for Festo Didactic SE MES PC. The source metadata says specially crafted SQL statements can trigger the issue in MariaDB Server v10.6.2 and below. Because the CVSS vector is network-exploitable, requires no privileges, and has high availability [truncated]
CVE-2022-27378 is a high-severity denial-of-service issue referenced in a CISA CSAF advisory for Festo Didactic SE MES PC. The source record’s vulnerability text describes a MariaDB Server flaw involving specially crafted SQL statements, while the advisory remediation points MES PC users to a vendor replacement path.
CVE-2022-27377 is a high-severity use-after-free issue described in the Festo Didactic MES PC advisory corpus. The advisory text says MariaDB Server v10.6.3 and below is affected in Item_func_in::cleanup(), with exploitation possible via specially crafted SQL statements. Festo’s remediation guidance points to Factory Control Panel as a replacement for XAMPP on MES PCs and directs customers to obtain the c [truncated]
CVE-2022-27376 is a high-severity use-after-free in MariaDB's Item_args::walk_arg that can be triggered by specially crafted SQL statements. In the supplied CISA/Festo advisory context, it is tied to Festo Didactic SE MES PC deployments that used XAMPP; Festo's remediation is to move to Factory Control Panel, which the vendor says includes fixes.
CVE-2022-23808 is a medium-severity web injection issue tied to phpMyAdmin 5.1 before 5.1.2 and republished by CISA in a Festo Didactic SE MES PC advisory. The reported impact is that an attacker can inject malicious code into parts of the setup script, which can lead to XSS or HTML injection. For affected MES PC deployments, the vendor remediation referenced in the advisory is to move to Festo's Factory [truncated]
CVE-2022-23807 is a medium-severity authentication weakness tied in the supplied CISA/Festo advisory context to Festo Didactic SE MES PC. The advisory describes a phpMyAdmin issue where a valid user who is already authenticated can manipulate their account to bypass two-factor authentication on future login instances. The source remediation points to a replacement Factory Control Panel that includes fixes [truncated]
CVE-2022-21595 is a Medium-severity Oracle MySQL Server vulnerability in the C API component that can lead to a hang or repeatable crash, resulting in denial of service. The source advisory ties it to Festo Didactic SE MES PC and says the replacement Factory Control Panel includes fixes. Exploitation is described as difficult and requires a high-privilege attacker with network access via multiple protocols.
CVE-2021-46669 is a high-severity denial-of-service vulnerability described by CISA as a MariaDB use-after-free in convert_const_to_int when BIGINT is used. In the Festo Didactic SE advisory context, the issue is associated with MES PC deployments and the vendor’s replacement guidance for XAMPP-based systems. Because the published CVSS vector is network-reachable with no privileges or user interaction req [truncated]
CVE-2021-46668 is an availability-impacting MariaDB issue that can cause an application crash when certain long SELECT DISTINCT statements interact badly with storage-engine limits for temporary data structures. In the CISA CSAF advisory corpus, the issue is mapped to Festo Didactic SE’s MES PC environment, and Festo’s remediation points to replacing XAMPP with Factory Control Panel on MES PCs. The publis [truncated]
CVE-2021-46667 describes an integer overflow in MariaDB's sql_lex.cc code path before 10.6.5 that can cause an application crash. In the supplied CISA CSAF advisory corpus, the issue is associated with Festo Didactic SE MES PC and a vendor replacement path through Factory Control Panel. The published CVSS vector is local and availability-only, so the main risk is loss of service rather than data compromise.
The supplied government advisory associates CVE-2021-46666 with Festo Didactic SE MES PC and describes an availability-impacting crash condition. The remediation guidance points to a vendor-released replacement for Factory Control Panel on MES PCs. The source corpus is worth reading carefully because the CVE description text also references a MariaDB crash condition, so asset applicability should be verif [truncated]
CVE-2021-46665 is a denial-of-service issue tied in the advisory corpus to Festo Didactic SE MES PC systems that use a MariaDB component. The CVE description says MariaDB through 10.5.9 can crash in sql_parse.cc because of incorrect used_tables expectations. The supplied CVSS vector is local, low-privilege, and availability-focused, so the main concern is service disruption on affected MES PC hosts rather [truncated]
CVE-2021-46664 is a medium-severity availability issue described in the supplied advisory corpus as a MariaDB crash in sub_select_postjoin_aggr when aggr is NULL. In the CISA-republished Festo Didactic SE MES PC advisory context, the vendor recommends replacing the vulnerable XAMPP-based MES PC component with Factory Control Panel, which includes fixes. The supplied CVSS vector indicates a local, low-priv [truncated]
CVE-2021-46663 is a medium-severity availability issue involving MariaDB through 10.5.13, where certain SELECT statements can trigger a ha_maria::extra crash. In the supplied CISA CSAF advisory, the issue is associated with Festo Didactic SE MES PC and a vendor replacement path through Factory Control Panel for MES PCs.
CVE-2021-46662 is a medium-severity availability issue in MariaDB through 10.5.9. According to the supplied CISA CSAF advisory for Festo Didactic SE MES PC, certain UPDATE statements combined with nested subqueries can crash set_var.cc, which can disrupt affected systems even without data exposure.
CVE-2021-46661 describes a denial-of-service condition in MariaDB through 10.5.9 that can crash query-processing paths when an unused common table expression (CTE) is present. In the Festo Didactic SE MES PC advisory context, this maps to an application crash in find_field_in_tables and find_order_in_list, so the primary risk is loss of availability rather than data exposure or code execution. The source [truncated]