PatchSiren cyber security CVE debrief
CVE-2024-6351 Schneider Electric CVE debrief
CVE-2024-6351 is a medium-severity Schneider Electric Zigbee advisory issue published by CISA on 2026-01-13. The disclosed weakness is a CWE-120 buffer overflow that can cause a denial of service when a malicious device joins the network. The published CVSS vector (4.3, AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) indicates adjacent-network conditions and availability-only impact.
- Vendor
- Schneider Electric
- Product
- Wiser iTRV2
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-01-27
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-01-27
Who should care
Schneider Electric customers and operators using Wiser iTRV2, and teams managing Zigbee device pairing or network-join settings across the broader Schneider Electric Zigbee product set listed in the advisory.
Technical summary
The advisory describes a buffer overflow in Zigbee product handling that may be triggered when a malicious device joins the network. Based on the published vector, the issue requires adjacent-network conditions and does not affect confidentiality or integrity, but it can disrupt availability.
Defensive priority
Medium — address during the normal maintenance cycle, but prioritize sooner if Zigbee pairing is routinely enabled or device admission is difficult to tightly control.
Recommended defensive actions
- Restrict device access so unknown devices cannot join the Zigbee network.
- Review hub settings to confirm how device pairing and admission are controlled.
- Only open the network when adding new devices, and close it immediately afterward.
- Use install codes where possible and avoid the well-known key.
- Replace default keys with secure, unique keys.
- Inventory whether Wiser iTRV2 or other Schneider Electric Zigbee products from the advisory are in use, and apply vendor guidance to each affected product.
- Monitor the Schneider Electric notice and the CISA advisory for any updates or revised remediation guidance.
Evidence notes
The source corpus identifies CISA advisory ICSA-26-027-03 and Schneider Electric’s SEVD-2026-013-03 notice as the primary sources. The advisory metadata lists CVE-2024-6351, describes a CWE-120 buffer overflow leading to denial of service when a malicious device joins the network, and provides the CVSS 3.1 vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L (score 4.3). The advisory was initially published on 2026-01-13 and republished by CISA on 2026-01-27 from Schneider Electric’s original notice. The remediation text in the source specifically recommends restricting device access, reviewing hub settings, limiting when the network is open for pairing, and using install codes and unique keys.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6351 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6351
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6351 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6351
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.