PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-10106 Schneider Electric CVE debrief

CVE-2024-10106 is a low-severity availability issue in Schneider Electric Wiser Zigbee products. The advisory says a CWE-120 buffer overflow can cause denial of service if a malicious device joins the network. The published CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) indicates network reachability, no privileges, and limited availability impact, with no confidentiality or integrity impact identified in the supplied sources.

Vendor
Schneider Electric
Product
Wiser iTRV2
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-13
Original CVE updated
2026-01-27
Advisory published
2026-01-13
Advisory updated
2026-01-27

Who should care

Organizations and households that use Schneider Electric Wiser Zigbee products, especially administrators, installers, and anyone responsible for device pairing or network access controls on Wiser iTRV2 and the related affected product family.

Technical summary

The supplied CSAF advisory for Schneider Electric identifies a buffer overflow in the Zigbee product line, with CVE-2024-10106 specifically mapped to Wiser iTRV2. The issue can lead to denial of service when a malicious device joins the network. CISA’s republished advisory and the Schneider Electric notice recommend limiting device-join access, reviewing hub pairing settings, opening the network only when pairing new devices, and using install codes and unique keys instead of the well-known default key.

Defensive priority

Low to Moderate

Recommended defensive actions

  • Restrict Zigbee device joining so unknown devices cannot pair with the network.
  • Review hub settings to confirm how device pairing is managed and who can authorize joins.
  • Only open the network when adding devices, then close it immediately afterward.
  • Use install codes and replace default or well-known keys with unique, secure keys.
  • Follow Schneider Electric notice SEVD-2026-013-03 and CISA advisory ICSA-26-027-03 for product-specific guidance across the affected Wiser device set.

Evidence notes

Supported by the CISA CSAF advisory ICSA-26-027-03 and the Schneider Electric SEVD-2026-013-03 references. The source text explicitly states a CWE-120 buffer overflow that can cause denial of service when a malicious device joins the network. The supplied CVSS vector indicates network exposure, high attack complexity, no privileges, no user interaction, and low availability impact only. CISA’s revision history shows an initial release on 2026-01-13 and a republication on 2026-01-27.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-10106 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-10106

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-10106 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10106

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.