PatchSiren cyber security CVE debrief
CVE-2024-6350 Schneider Electric CVE debrief
CVE-2024-6350 is a medium-severity buffer overflow issue in Schneider Electric Zigbee products, including Wiser iTRV2. According to the advisory, a malicious device joining the network could trigger a denial of service. The published mitigations focus on tightening Zigbee pairing and access controls rather than on exploit details.
- Vendor
- Schneider Electric
- Product
- Wiser iTRV2
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-01-27
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-01-27
Who should care
Organizations using Schneider Electric Zigbee products, especially Wiser iTRV2 deployments; building automation and OT teams; and administrators responsible for Zigbee pairing, device onboarding, and network key management.
Technical summary
The advisory describes a CWE-120 buffer overflow that can lead to denial of service when a malicious device joins the network. The supplied CVSS vector is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which indicates an adjacent-network attack with high availability impact and no confidentiality or integrity impact. The CSAF advisory lists Wiser iTRV2 among 34 Schneider Electric Zigbee products covered by the notice.
Defensive priority
Medium overall; prioritize sooner in environments where Zigbee join access is routinely opened, pairing controls are weak, or untrusted devices could reach the network.
Recommended defensive actions
- Do not allow unknown devices to join the Zigbee network.
- Review hub settings and how device pairing is managed.
- Only open the network when adding new devices, and close it immediately afterward.
- Use unique install codes where possible and avoid the well-known key; replace default keys with secure, unique keys.
- Review the Schneider Electric and CISA advisories for product-specific guidance and any updated mitigation notes.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-26-027-03 and the linked Schneider Electric SEVD-2026-013-03 notice. The source states that a CWE-120 buffer overflow can cause denial of service when a malicious device joins the network. The advisory’s product tree includes Wiser iTRV2 and many other Schneider Electric Zigbee products, and its remediation section recommends restricting device access, managing pairing windows, and using install codes/unique keys. The supplied CVSS vector is AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (6.5 medium).
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6350 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6350
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6350 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6350
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.