PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-45492 Siemens CVE debrief

CVE-2024-45492 is a High-severity integer overflow issue in libexpat that Siemens lists in its ICS advisory for the RUGGEDCOM RST2428P and related product families. The flaw is described as occurring in nextScaffoldPart in xmlparse.c before libexpat 2.6.3, and it is specifically noted to affect 32-bit platforms where UINT_MAX equals SIZE_MAX. Siemens recommends updating affected products to V3.1 or later.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Operators and maintainers of Siemens deployments named in the advisory, especially RUGGEDCOM RST2428P (6GK6242-6PA00) and the other listed Siemens families, should review exposure. OT/ICS security teams should also care if their environment uses libexpat on 32-bit platforms or processes untrusted XML through affected Siemens software.

Technical summary

The advisory describes an integer overflow in libexpat's xmlparse.c path, in nextScaffoldPart, involving m_groupSize. The condition is called out for 32-bit platforms where UINT_MAX equals SIZE_MAX. CISA's CSAF record rates the issue CVSS 7.3 High with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating network-reachable exposure with low confidentiality, integrity, and availability impact.

Defensive priority

High — prioritize affected Siemens OT assets, especially where the vulnerable library path may be reachable through attacker-controlled input. Siemens provides a vendor fix path, so patching should be scheduled promptly after validating product/version applicability.

Recommended defensive actions

  • Confirm whether any Siemens products listed in the advisory are deployed, including RUGGEDCOM RST2428P and the other named families.
  • Apply Siemens' recommended update path and move affected products to V3.1 or later.
  • Pay special attention to 32-bit deployments, which are the platform condition explicitly identified in the advisory.
  • Review any XML-processing exposure paths and reduce trust in externally supplied input until remediation is complete.
  • Use the Siemens and CISA advisories to verify exact product/version applicability before maintenance windows.

Evidence notes

Source corpus states: 'An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).' The CISA CSAF advisory (ICSA-25-226-15) was initially published on 2025-08-12 and later republished on 2026-02-25 based on Siemens ProductCERT advisory SSA-613116. The advisory's remediation field directs users to update to V3.1 or later for affected products.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-45492 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-45492

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-45492 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45492

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.