PatchSiren cyber security CVE debrief
CVE-2020-24588 Siemens CVE debrief
CVE-2020-24588 describes a Wi-Fi integrity issue in the 802.11 handling of A-MSDU frames. In affected Siemens SCALANCE wireless devices, an attacker within Wi-Fi range may abuse the unauthenticated A-MSDU flag to inject arbitrary network packets. Siemens’ mitigation path is to update to V6.6.0 or later and, where possible, disable A-MSDU or reduce wireless exposure.
- Vendor
- Siemens
- Product
- SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0)
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-14
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-14
- Advisory updated
- 2026-04-21
Who should care
OT/ICS operators, network defenders, and site administrators responsible for Siemens SCALANCE wireless infrastructure should review this issue, especially where devices operate in reachable RF areas and accept non-SSP A-MSDU frames.
Technical summary
The source advisory states that the 802.11 standard does not require authentication of the A-MSDU flag in the plaintext QoS header field. Against devices that support receiving non-SSP A-MSDU frames, which is mandatory as part of 802.11n, an adversary can abuse this weakness to inject arbitrary network packets. The advisory lists multiple Siemens SCALANCE W7xx wireless models as affected when running versions earlier than V6.6.0, and identifies V6.6.0 or later as the vendor fix.
Defensive priority
Medium
Recommended defensive actions
- Upgrade affected Siemens SCALANCE devices to V6.6.0 or later, per the vendor advisory.
- Disable A-MSDU if the device and deployment allow it.
- Reduce Wi-Fi transmission power where possible to limit attack range.
- Place affected devices in private or physically controlled areas when feasible.
- Review wireless exposure for the listed SCALANCE models and prioritize systems that cannot be easily isolated.
- Validate that compensating controls and monitoring cover packet-injection risk on trusted wireless links.
Evidence notes
Timing context comes from the supplied advisory record: CISA’s ICSA-26-111-07 was published on 2026-04-14 and republished on 2026-04-21, with the source advisory attributed to Siemens ProductCERT SSA-019200. The supplied CVSS vector is CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, matching a low-severity integrity-focused issue that requires nearby wireless access. The remediation text in the source explicitly recommends updating to V6.6.0 or later, disabling A-MSDU if possible, and reducing transmission power or using physical access controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2020-24588 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2020-24588
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2020-24588 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-24588
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-019200.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-019200.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.