These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CISA’s republished advisory for Festo Didactic SE MES PC identifies CVE-2021-35604 as an Oracle MySQL InnoDB issue with availability and limited integrity impact. The advisory says affected versions include MySQL 5.7.35 and prior, and 8.0.26 and prior, and that successful attacks can cause a hang or repeatable crash as well as unauthorized insert, update, or delete activity on some accessible data. Festo’ [truncated]
CVE-2021-27928 is a high-severity remote code execution issue that the supplied CISA CSAF advisory maps to Festo Didactic SE MES PC. The advisory text describes an untrusted search path leading to eval injection in MariaDB/Percona/wsrep-related components, where a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. Festo’s remediation entry in the source corpus [truncated]
The supplied advisory corpus describes a medium-severity denial-of-service issue tied to Oracle MySQL Server's InnoDB component. It says an unauthenticated attacker with network access via multiple protocols could cause a hang or frequently repeatable crash, resulting in complete denial of service. The source advisory is associated with Festo Didactic SE's MES PC product tree entry, and the published reme [truncated]
CVE-2021-2372 is a medium-severity availability issue that can cause a hang or repeatable crash of MySQL Server. In the source advisory, CISA maps the issue to Festo Didactic SE MES PC and notes that Festo replaced XAMPP with Factory Control Panel as the fix path for affected systems. Because exploitation requires a high-privileged attacker with network access, the main risk is operational downtime rather [truncated]
CVE-2021-2194 is an availability issue described in the supplied corpus as affecting Oracle MySQL Server InnoDB, with a network-accessible high-privilege attack path that can cause a hang or repeatable crash. The advisory context is published under Festo Didactic SE MES PC, and the source remediation points to a Factory Control Panel replacement path that includes fixes.
CVE-2021-2180 is described in the supplied record as a network-reachable MySQL Server/InnoDB issue that can let a high-privilege attacker trigger a hang or repeatable crash, resulting in complete denial of service. The same CISA CSAF source also associates the CVE with Festo Didactic SE MES PC and recommends replacing XAMPP with Factory Control Panel as the vendor fix path. Because the source description [truncated]
CVE-2021-2174 is a medium-severity availability issue tied in the source corpus to Festo Didactic MES PC and an upstream Oracle MySQL InnoDB component. The CVE text says a high-privileged attacker with network access via multiple protocols can cause MySQL Server to hang or repeatedly crash, resulting in complete denial of service. Supported Oracle MySQL versions cited as affected are 5.7.33 and prior, and [truncated]
CVE-2021-21708 is a critical use-after-free in PHP’s FILTER_VALIDATE_FLOAT handling when min/max limits are used and the filter fails. In the supplied Festo Didactic SE advisory context, this issue is mapped to MES PC systems that relied on the affected PHP/XAMPP stack. The documented remediation is to move MES PC deployments to Festo’s Factory Control Panel replacement, which the advisory says includes fixes.
CVE-2021-21707 describes a PHP filename-handling flaw in certain XML parsing functions, including simplexml_load_file(). When a filename is URL-decoded and contains a URL-encoded NUL byte, PHP may treat the NUL as the end of the filename and open a different file than the caller intended. In the Festo Didactic SE MES PC advisory context, the vendor directs operators to a replacement Factory Control Panel [truncated]
CVE-2021-21706 describes a Windows-specific PHP ZipArchive::extractTo weakness that can allow files from a ZIP archive to be written outside the intended extraction directory. In Festo Didactic SE MES PC advisories, this matters because the affected deployment context can expose integrity risk on systems handling untrusted archives, especially where OS permissions allow overwrite or file creation.
CVE-2021-21705 is a PHP URL-validation flaw that can accept an URL with an invalid password field as valid when filter_var() is used with FILTER_VALIDATE_URL. In affected environments, that can cause incorrect URL parsing and lead to integrity-impacting mistakes such as contacting the wrong server or making the wrong access decision.
CVE-2021-21704 is a PHP Firebird PDO driver flaw that can let a malicious database server trigger crashes in functions such as getAttribute(), execute(), and fetch(). In Festo Didactic SE MES PC deployments that include the affected PHP component, the practical impact is denial of service, with potential memory corruption noted in the advisory.
CVE-2021-21703 is a high-severity local privilege-escalation issue tied in CISA’s advisory to Festo Didactic SE MES PC deployments that use vulnerable PHP-FPM versions. In the affected PHP ranges, a lower-privileged worker can alter shared memory in a way that can trigger invalid reads and writes in the root-owned master process, creating a path to root compromise on the host.
CVE-2021-21702 is a PHP denial-of-service vulnerability that can crash affected PHP processes when the SOAP extension parses malformed XML returned by a malicious SOAP server. In the CISA-republished Festo Didactic SE advisory, the issue is associated with MES PC environments and a replacement Factory Control Panel release. The primary risk is loss of availability, not data theft or code execution.
CVE-2021-2166 is a denial-of-service issue in MySQL Server that, in the supplied CISA CSAF advisory, is mapped to Festo Didactic SE MES PC. A high-privileged attacker with network access can trigger a hang or repeatable crash, which can interrupt service availability. The supplier remediation points MES PC users to a current Factory Control Panel release that replaces XAMPP.
CVE-2021-2154 is a denial-of-service issue described in the supplied Festo Didactic SE MES PC advisory corpus. The affected component is the underlying Oracle MySQL Server DML path, and successful exploitation can cause a hang or a repeatedly reproducible crash of the MySQL Server process. The advisory says the attack requires high privileges and network access, so this is not a low-skill or unauthenticat [truncated]
CVE-2021-2144 is a high-severity Oracle MySQL Server vulnerability called out in the supplied Festo Didactic SE MES PC advisory context. The advisory describes a network-reachable issue in the MySQL Server parser component, notes that exploitation is easy for a high-privileged attacker using multiple protocols, and states that successful attacks can lead to takeover of MySQL Server. For MES PC deployments [truncated]
CVE-2021-2032 is a medium-severity information disclosure issue in Oracle MySQL Server that CISA republished in a Festo Didactic SE MES PC advisory. According to the supplied advisory text, an attacker with low privileges and network access could read a subset of MySQL Server-accessible data. The vendor remediation points to replacing XAMPP with Factory Control Panel for affected MES PCs.
CVE-2021-2022 is publicly documented in the supplied CISA/Festo advisory context as a MySQL Server InnoDB issue that can let a highly privileged network attacker trigger a hang or repeatable crash, resulting in denial of service. The advisory context is Festo Didactic SE MES PC, and the supplied remediation points customers to a replacement Factory Control Panel release that includes fixes.
CVE-2021-2011 is a network-reachable denial-of-service vulnerability in Oracle MySQL Client’s C API. In the supplied CISA CSAF advisory, it is associated with Festo Didactic SE’s MES PC product context, and successful exploitation can cause the client to hang or repeatedly crash. The advisory rates the issue CVSS 5.9 (medium) and notes that exploitation is difficult but does not require authentication.
CVE-2021-2007 is a low-severity vulnerability described in a Festo Didactic SE MES PC advisory that points to Oracle MySQL Client (C API) versions 5.6.47 and earlier, 5.7.29 and earlier, and 8.0.19 and earlier. The advisory says a remote, unauthenticated attacker with network access via multiple protocols could compromise the client and obtain read access to a subset of accessible data. Festo’s remediatio [truncated]
CVE-2020-7071 is a PHP URL-parsing issue that the supplied advisory maps to Festo Didactic SE MES PC deployments. PHP's filter_var($url, FILTER_VALIDATE_URL) may accept a URL with an invalid password section as valid, which can cause downstream code to mis-read the URL and use the wrong components. In an MES PC context, that is primarily an integrity and trust problem for any logic that relies on URL vali [truncated]
CVE-2020-7070 is a PHP cookie-handling flaw that can cause cookie names to be URL-decoded during request processing. In affected PHP versions, that behavior can make attacker-controlled cookies look like secure prefix-based cookies such as __Host, creating a risk of cookie forgery and integrity compromise. In the supplied CISA advisory, the issue is mapped to Festo Didactic SE MES PC, with remediation poi [truncated]
CVE-2020-7069 describes a PHP OpenSSL issue in which AES-CCM encryption with a 12-byte IV uses only the first 7 bytes of the IV in affected PHP releases. That can weaken cryptographic security and produce incorrect encrypted data. In the supplied CISA CSAF advisory, the impacted product context is Festo Didactic SE MES PC, where Festo points users to a Factory Control Panel replacement for XAMPP on MES PC [truncated]
CVE-2020-7068 describes a use-after-free in PHP's phar extension when parsing PHAR ZIP files. In the supplied Festo MES PC advisory context, the practical concern is exposure on systems still running the affected PHP/XAMPP stack. The issue is low severity overall, but it can still cause a crash or limited information disclosure, so affected deployments should move to the vendor-recommended replacement sof [truncated]
CVE-2020-7066 is a medium-severity PHP URL-handling flaw that the supplied CISA CSAF advisory maps to Festo Didactic SE MES PC. When get_headers() is called with a user-supplied URL, a NUL byte can cause the URL to be silently truncated, which may make software believe it is interacting with one target while actually reaching another. In an MES/OT context, that can lead to misdirected requests and limited [truncated]
CVE-2020-7065 is a memory-corruption issue in PHP that can be triggered when mb_strtolower() is used with UTF-32LE encoding on certain invalid strings. In the supplied advisory corpus, CISA republished the issue in the context of Festo Didactic SE MES PC, with vendor guidance to replace XAMPP on affected MES PCs with Factory Control Panel. The reported impact includes crashes, memory corruption, and possi [truncated]
This advisory covers a low-complexity PHP EXIF parsing bug that can read one byte of uninitialized memory when exif_read_data() processes malicious data. For Festo Didactic SE MES PC environments, the practical concern is exposure through the affected PHP stack, with potential for limited information disclosure or a crash. The vendor-referenced remediation path is to move to the fixed Factory Control Pane [truncated]
CISA’s Festo Didactic SE MES PC advisory includes CVE-2020-7063, a PHP PHAR archive permission issue that can preserve files at a default 0666 permission level when using PharData::buildFromIterator(). For MES PC environments that still rely on affected PHP builds, extracted files may end up with broader access than intended, which is a hardening and integrity concern. The advisory points to Factory Contr [truncated]
CVE-2020-7062 is a denial-of-service flaw in PHP file upload progress cleanup handling. In the supplied advisory, a failed upload can trigger a null pointer dereference when upload progress tracking is enabled and session.upload_progress.cleanup is set to 0, which would likely crash the service. CISA’s CSAF record maps the issue to Festo Didactic SE MES PC and directs users to the vendor’s replacement/fix [truncated]