PatchSiren cyber security CVE debrief
CVE-2024-10106 Schneider Electric CVE debrief
CVE-2024-10106 is a low-severity availability issue in Schneider Electric Wiser Zigbee products. The advisory says a CWE-120 buffer overflow can cause denial of service if a malicious device joins the network. The published CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) indicates network reachability, no privileges, and limited availability impact, with no confidentiality or integrity impact identified in the supplied sources.
- Vendor
- Schneider Electric
- Product
- Wiser iTRV2
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-01-27
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-01-27
Who should care
Organizations and households that use Schneider Electric Wiser Zigbee products, especially administrators, installers, and anyone responsible for device pairing or network access controls on Wiser iTRV2 and the related affected product family.
Technical summary
The supplied CSAF advisory for Schneider Electric identifies a buffer overflow in the Zigbee product line, with CVE-2024-10106 specifically mapped to Wiser iTRV2. The issue can lead to denial of service when a malicious device joins the network. CISA’s republished advisory and the Schneider Electric notice recommend limiting device-join access, reviewing hub pairing settings, opening the network only when pairing new devices, and using install codes and unique keys instead of the well-known default key.
Defensive priority
Low to Moderate
Recommended defensive actions
- Restrict Zigbee device joining so unknown devices cannot pair with the network.
- Review hub settings to confirm how device pairing is managed and who can authorize joins.
- Only open the network when adding devices, then close it immediately afterward.
- Use install codes and replace default or well-known keys with unique, secure keys.
- Follow Schneider Electric notice SEVD-2026-013-03 and CISA advisory ICSA-26-027-03 for product-specific guidance across the affected Wiser device set.
Evidence notes
Supported by the CISA CSAF advisory ICSA-26-027-03 and the Schneider Electric SEVD-2026-013-03 references. The source text explicitly states a CWE-120 buffer overflow that can cause denial of service when a malicious device joins the network. The supplied CVSS vector indicates network exposure, high attack complexity, no privileges, no user interaction, and low availability impact only. CISA’s revision history shows an initial release on 2026-01-13 and a republication on 2026-01-27.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-10106 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-10106
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-10106 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10106
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.