PatchSiren cyber security CVE debrief
CVE-2024-47619 Siemens CVE debrief
CVE-2024-47619 describes a TLS certificate hostname-checking flaw where syslog-ng’s wildcard matcher accepted invalid patterns such as "foo.*.bar" and partial wildcards like "foo.a*c.bar". In the Siemens/CISA advisory context, the issue is mapped to SINEC OS firmware on affected RUGGEDCOM and SCALANCE products. Because the flaw is network-reachable and can affect TLS connection trust, it matters most where these devices rely on certificate validation for secure management or data exchange.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-28
- Original CVE updated
- 2026-02-25
- Advisory published
- 2026-01-28
- Advisory updated
- 2026-02-25
Who should care
Operators and maintainers of Siemens industrial networking equipment, especially environments running the affected SINEC OS firmware on listed RUGGEDCOM and SCALANCE products. OT security teams, network administrators, and asset owners responsible for TLS-secured device communication should prioritize review.
Technical summary
The flaw is a certificate wildcard matching error in tls_wildcard_match() that can incorrectly treat disallowed wildcard certificates as valid. The supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) indicates a network-exploitable issue with no privileges or user interaction required and a primary integrity impact. The advisory’s revision history later clarifies that only SINEC OS firmware is impacted and expands the affected product list. Siemens’ remediation is to update impacted products to V3.3 or later.
Defensive priority
High. Prioritize if any affected Siemens product is deployed in a TLS-trusting role, especially in OT environments where certificate validation is used to protect management or telemetry traffic.
Recommended defensive actions
- Inventory Siemens RUGGEDCOM and SCALANCE devices and confirm whether they run the affected SINEC OS firmware.
- Apply Siemens’ recommended update to V3.3 or later on impacted products.
- Validate that deployed certificates and hostname-matching rules do not rely on invalid or partial wildcard patterns.
- Review TLS trust paths and management-plane access to reduce exposure to interception or certificate spoofing.
- Monitor Siemens ProductCERT and the CISA republication for any further scope clarifications or update guidance.
Evidence notes
Primary evidence comes from the CISA CSAF source item and Siemens ProductCERT references tied to ICSA-26-043-06 / SSA-089022. The supplied revision history shows the advisory was first published on 2026-01-28, later republished, and then clarified on 2026-02-24/2026-02-25 to state that only SINEC OS firmware is impacted while adding additional affected product families. No KEV listing or ransomware linkage was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-47619 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-47619
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-47619 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47619
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.