PatchSiren cyber security CVE debrief
CVE-2024-45492 Siemens CVE debrief
CVE-2024-45492 is a High-severity integer overflow issue in libexpat that Siemens lists in its ICS advisory for the RUGGEDCOM RST2428P and related product families. The flaw is described as occurring in nextScaffoldPart in xmlparse.c before libexpat 2.6.3, and it is specifically noted to affect 32-bit platforms where UINT_MAX equals SIZE_MAX. Siemens recommends updating affected products to V3.1 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of Siemens deployments named in the advisory, especially RUGGEDCOM RST2428P (6GK6242-6PA00) and the other listed Siemens families, should review exposure. OT/ICS security teams should also care if their environment uses libexpat on 32-bit platforms or processes untrusted XML through affected Siemens software.
Technical summary
The advisory describes an integer overflow in libexpat's xmlparse.c path, in nextScaffoldPart, involving m_groupSize. The condition is called out for 32-bit platforms where UINT_MAX equals SIZE_MAX. CISA's CSAF record rates the issue CVSS 7.3 High with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating network-reachable exposure with low confidentiality, integrity, and availability impact.
Defensive priority
High — prioritize affected Siemens OT assets, especially where the vulnerable library path may be reachable through attacker-controlled input. Siemens provides a vendor fix path, so patching should be scheduled promptly after validating product/version applicability.
Recommended defensive actions
- Confirm whether any Siemens products listed in the advisory are deployed, including RUGGEDCOM RST2428P and the other named families.
- Apply Siemens' recommended update path and move affected products to V3.1 or later.
- Pay special attention to 32-bit deployments, which are the platform condition explicitly identified in the advisory.
- Review any XML-processing exposure paths and reduce trust in externally supplied input until remediation is complete.
- Use the Siemens and CISA advisories to verify exact product/version applicability before maintenance windows.
Evidence notes
Source corpus states: 'An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).' The CISA CSAF advisory (ICSA-25-226-15) was initially published on 2025-08-12 and later republished on 2026-02-25 based on Siemens ProductCERT advisory SSA-613116. The advisory's remediation field directs users to update to V3.1 or later for affected products.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-45492 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-45492
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-45492 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45492
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.