These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2020-7061 is a critical PHP PHAR extraction vulnerability that can affect Festo Didactic SE MES PC deployments using the vulnerable component stack. On Windows, certain PHAR content can trigger a one-byte read past the allocated buffer, creating a risk of information disclosure or a crash. CISA’s advisory rates the issue 9.1 (Critical), and Festo’s remediation path is to move MES PC environments to th [truncated]
CVE-2020-7060 is an out-of-bounds read in PHP’s mbstring conversion path, specifically mbfl_filt_conv_big5_wchar, when processing certain multibyte encodings. In the supplied CISA CSAF record, the issue is mapped to Festo Didactic SE MES PC and described as potentially causing information disclosure or a crash.
CVE-2020-7059 describes a PHP fgetss() buffer over-read that can lead to information disclosure or a crash. In the CISA advisory for Festo Didactic SE MES PC, the vendor points users to a replacement Factory Control Panel for XAMPP on MES PCs and says the current version includes fixes.
CVE-2020-2922 is a low-severity information disclosure issue affecting Oracle MySQL Client C API as described in the supplied advisory corpus. The advisory text says an unauthenticated network attacker using multiple protocols could compromise the client and read a subset of accessible data. In the CISA CSAF republish, the advisory is presented in a Festo Didactic SE MES PC context, with vendor remediatio [truncated]
CVE-2020-2814 is a medium-severity denial-of-service issue mapped in the supplied CISA CSAF advisory for Festo Didactic SE MES PC. The underlying flaw is described as affecting Oracle MySQL Server’s InnoDB component, where a high-privileged attacker with network access via multiple protocols can force a hang or repeatable crash. The practical risk is service disruption rather than data theft or code execution.
CVE-2020-2812 is an Oracle MySQL Server vulnerability in the Stored Procedure component that can be used by a high-privileged attacker with network access to trigger a hang or repeatable crash of MySQL Server. The supplied CVSS vector shows an availability-only impact, with no confidentiality or integrity impact recorded. In the supplied CISA CSAF advisory context, the issue is tied to Festo Didactic SE M [truncated]
The supplied advisory corpus links CVE-2020-2780 to Festo Didactic SE MES PC and describes a network-reachable denial-of-service condition that can let a low-privileged attacker cause a hang or repeatable crash of the MySQL Server component. The advisory notes that supported Oracle MySQL versions at issue were 5.6.47 and earlier, 5.7.29 and earlier, and 8.0.19 and earlier. Festo’s stated remediation is to [truncated]
CVE-2020-2760 is described in the source advisory as a MySQL Server/InnoDB vulnerability that can be abused by a high-privileged attacker with network access over multiple protocols. The reported outcomes include a repeatable server crash or hang, plus limited unauthorized data modification on affected MySQL Server installations. In the supplied CISA/Festo advisory context, this CVE is republished for Fes [truncated]
CVE-2020-2752 is a medium-severity denial-of-service vulnerability in Oracle MySQL Client's C API. In the Festo Didactic SE advisory context, the issue is tied to MES PC deployments that rely on the affected MySQL client components. The impact described in the source material is a hang or frequently repeatable crash of the client, which can disrupt availability but is not described as a confidentiality or [truncated]
CVE-2019-9641 is a critical PHP EXIF flaw involving an uninitialized read in exif_process_IFD_in_TIFF. The supplied CISA/Festo advisory ties the issue to Festo Didactic SE MES PC deployments and says the replacement Factory Control Panel includes fixes for these vulnerabilities. For affected environments, remediation is urgent.
CVE-2019-9640 is a high-severity memory-safety issue in PHP’s EXIF component that the CISA advisory maps to Festo Didactic SE’s MES PC environment. The source describes an invalid read in exif_process_SOFn, and the advisory points operators to the vendor replacement path for bundled XAMPP-related software.
CVE-2019-9639 is a high-severity PHP EXIF vulnerability involving an uninitialized read in exif_process_IFD_in_MAKERNOTE. In the supplied CISA CSAF advisory, the issue is mapped to Festo Didactic SE MES PC deployments that relied on bundled PHP/XAMPP components. Festo’s stated remediation path is to replace XAMPP with Factory Control Panel and obtain the current version through vendor support.
CVE-2019-9638 is a confidentiality-impacting memory disclosure issue in PHP's EXIF processing. In the supplied CISA/Festo advisory context, it is associated with Festo Didactic SE MES PC systems that rely on the affected software stack. Because the issue is network-reachable per the CVSS vector, requires no privileges or user interaction, and can expose memory contents, it should be treated as a high-prio [truncated]
CVE-2019-9637 is a PHP confidentiality issue that occurs during rename() operations across filesystems. While the move is in progress, the file can briefly be available with the wrong permissions, creating a window for unauthorized users to read data. The supplied CISA advisory also maps the issue to Festo Didactic SE’s MES PC and points operators to a vendor replacement path that includes fixes.
CVE-2019-9025 is a critical PHP memory-corruption issue affecting PHP 7.3.x before 7.3.1. In the supplied CSAF advisory, the issue is associated with Festo Didactic SE MES PC and a vendor remediation that replaces XAMPP with Factory Control Panel. The core risk is that an invalid multibyte string passed to mb_split() can lead PHP to call memcpy() with a negative argument, which may read and write past all [truncated]
Festo Didactic’s MES PC advisory maps CVE-2019-9024 to the PHP component used in its legacy XAMPP-based stack. The flaw lets a hostile XML-RPC server drive an out-of-bounds memory read in xmlrpc_decode(), creating a confidentiality risk for affected deployments. Festo’s documented remediation is to move MES PCs to the current Factory Control Panel release, which replaces XAMPP.
CVE-2019-9023 is a critical heap-based buffer over-read issue in PHP mbstring regular expression handling for invalid multibyte input. In the supplied CISA/Festo advisory corpus, the issue is associated with Festo Didactic SE MES PC deployments and the remediation path is to move to Factory Control Panel, which is described as the replacement for XAMPP on MES PCs and includes fixes. The CISA source item w [truncated]
CVE-2019-9022 describes an out-of-bounds read in PHP’s DNS handling, where dns_get_record can misparse a crafted DNS response and cause php_parserr to misuse memcpy. The issue is triggered by a hostile DNS server and affects DNS_CAA and DNS_ANY queries in ext/standard/dns.c. In the supplied Festo/CISA advisory context, the vulnerability is mapped to Festo Didactic SE MES PC, with remediation pointing to F [truncated]
CVE-2019-9021 is a critical memory-disclosure flaw in PHP’s PHAR file-reading logic. The issue can cause a heap-based buffer over-read while parsing a file name, allowing an attacker to read data past the intended boundary. In the supplied CISA CSAF advisory, the issue is mapped to Festo Didactic SE’s MES PC environment, with Festo directing customers to a replacement Factory Control Panel release that in [truncated]
CVE-2019-9020 is a critical PHP memory-safety issue that CISA republished in the context of Festo Didactic SE MES PC. The advisory ties the affected environment to a PHP/XAMPP-based stack and says Factory Control Panel replaces XAMPP on MES PCs and includes fixes. Organizations should verify whether any MES PC deployments still rely on the vulnerable component set and move to the vendor-supported replacem [truncated]
CVE-2019-11048 is a denial-of-service issue in affected PHP versions when HTTP file uploads are enabled. Oversized filenames or field names can push the PHP engine toward excessive memory allocation, hit the memory limit, and abort request processing without cleaning up temporary upload files. Over time, that can accumulate leftover files and exhaust disk space on the target system. The official advisory [truncated]
CVE-2019-11047 is a PHP EXIF parsing flaw that can cause an out-of-bounds read when processing crafted image metadata. In the supplied Festo Didactic SE MES PC advisory, CISA maps this issue to MES PC deployments and recommends replacing XAMPP with Factory Control Panel on affected MES PCs. The practical risk is information disclosure or a crash, with no indication in the supplied corpus of active exploit [truncated]
CVE-2019-11042 is an out-of-bounds read in PHP’s EXIF parsing path. In the Festo Didactic MES PC advisory context, the affected software stack is associated with Factory Control Panel/XAMPP on MES PCs. The flaw can cause information disclosure or a crash when EXIF data from an image is processed, including through functions such as exif_read_data().
CVE-2019-11041 is an out-of-bounds read in PHP's EXIF parser. When exif_read_data() processes crafted image metadata, affected PHP versions can read past an allocated buffer, which may leak memory contents or crash the process. In the supplied CISA/Festo advisory context, the issue is tied to Festo Didactic SE MES PC, and the documented remediation is a replacement Factory Control Panel for MES PCs that i [truncated]
CVE-2019-11040 is an out-of-bounds read in PHP's EXIF parsing path. In the supplied advisory, attacker-supplied image data can cause PHP to read past an allocated buffer, which may result in information disclosure or a crash. The CISA CSAF record maps the issue to Festo Didactic SE MES PC and cites remediation through Factory Control Panel as a replacement for XAMPP on those systems.
CVE-2019-11039 is a critical PHP flaw in iconv_mime_decode_headers() that can trigger an out-of-buffer read when parsing MIME headers. The result can be information disclosure or a crash. In the supplied CISA advisory corpus, the issue is associated with Festo Didactic SE MES PC deployments, with remediation centered on replacing XAMPP-based software with Festo’s Factory Control Panel.
CVE-2019-11036 is a critical PHP EXIF out-of-bounds read that can cause information disclosure or a crash when processing certain files. In the supplied CISA CSAF advisory, Festo Didactic SE maps this issue to MES PC deployments and recommends moving away from the affected XAMPP-based setup to Factory Control Panel. Defenders should verify whether any MES PC or related systems still rely on affected PHP E [truncated]
CVE-2019-11035 is a critical memory-safety issue in PHP's EXIF extension. When certain files are processed, exif_iif_add_value can read past an allocated buffer, which may expose memory contents or trigger a crash. In the Festo Didactic SE MES PC advisory, the affected environment is a MES PC platform tied to XAMPP, and Festo says its Factory Control Panel replacement includes fixes.
CVE-2019-11034 is a critical buffer over-read in the PHP EXIF extension’s exif_process_IFD_TAG function. In the supplied CISA CSAF advisory for Festo Didactic SE MES PC, the issue is described as affecting PHP 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4, with possible outcomes of information disclosure or a crash. The vendor remediation points to replacing XAMPP on MES PCs with Factory C [truncated]
CVE-2018-19935 is a high-severity availability issue in PHP’s ext/imap component: an empty string passed as the message argument to imap_mail can lead to a NULL pointer dereference and application crash. In the supplied CISA CSAF context, this appears in the Festo Didactic SE MES PC advisory stream, so operators should treat the issue as relevant wherever that product line depends on the vulnerable PHP stack.