PatchSiren cyber security CVE debrief
CVE-2024-50559 Siemens CVE debrief
A medium-severity vulnerability in Siemens SCALANCE M-800 family and RUGGEDCOM RM1224 industrial routers allows authenticated remote attackers to compromise system integrity by appending arbitrary values to certificate filenames due to improper input validation. The flaw was disclosed on November 12, 2024, with a vendor fix available requiring update to firmware version 8.2 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-11-12
- Advisory updated
- 2025-05-06
Who should care
Organizations operating Siemens SCALANCE M-800 series routers (including M804PB, M812-1, M816-1, M826-2, M874-2, M874-3, M876-3, M876-4, MUM853-1, MUM856-1 variants) and RUGGEDCOM RM1224 LTE routers in industrial, utility, transportation, or critical infrastructure environments. Security teams responsible for OT/ICS network infrastructure and certificate lifecycle management should prioritize this update.
Technical summary
CVE-2024-50559 is an input validation vulnerability affecting 26 Siemens industrial router products across the SCALANCE M-800 family and RUGGEDCOM RM1224 series. The flaw exists in the certificate filename validation mechanism, where improper sanitization allows authenticated remote attackers to append arbitrary values to certificate filenames. This integrity compromise could enable further attacks or system manipulation. The vulnerability requires user interaction and has a CVSS 3.1 score of 4.3 (Medium). Siemens has released firmware version 8.2 to address this issue across all affected product variants.
Defensive priority
medium
Recommended defensive actions
- Update affected Siemens SCALANCE M-800 family and RUGGEDCOM RM1224 devices to firmware version 8.2 or later as specified in the vendor security advisory.
- Apply network segmentation and restrict management interface access to trusted administrative hosts only.
- Monitor certificate management operations and file system integrity for unexpected filename modifications.
- Review and implement CISA ICS recommended practices for defense-in-depth strategies in industrial control environments.
Evidence notes
The vulnerability description and remediation guidance are sourced from CISA CSAF advisory ICSA-24-319-06, which references Siemens security advisory SSA-354112. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) indicates network attack vector with low attack complexity, no privileges required, user interaction required, and low integrity impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50559 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50559
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50559 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50559
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354112.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-354112.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.