PatchSiren cyber security CVE debrief
CVE-2024-50560 Siemens CVE debrief
CVE-2024-50560 is a Siemens SCALANCE W700 issue where usernames longer than 15 characters can be truncated when users connect over SSH or Telnet. According to the advisory, this may let an attacker affect system integrity. CISA lists the issue as low severity, but it still matters because it involves remote management access on affected industrial devices.
- Vendor
- Siemens
- Product
- SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-02-11
- Advisory updated
- 2025-05-06
Who should care
OT/ICS administrators, network security teams, and asset owners using the listed Siemens SCALANCE WAB/WAM/WUB/WUM devices should review this issue, especially where SSH or Telnet management access is enabled.
Technical summary
The advisory describes a username handling flaw in affected Siemens SCALANCE devices: usernames longer than 15 characters are truncated during SSH or Telnet access. That behavior can create an authentication or identity-handling mismatch and may allow an attacker to compromise system integrity. The supplied CVSS vector reflects network reachability, low attack complexity, low privileges, and integrity impact only.
Defensive priority
Moderate for exposed remote-management environments; otherwise lower. The CVSS score is LOW, but the flaw affects authentication-related access paths on industrial devices, so remediation should be tracked and applied on normal patch cycles without delay.
Recommended defensive actions
- Update affected devices to V3.0.0 or later, as directed by Siemens.
- Identify where the listed SCALANCE products are deployed and whether SSH or Telnet management is enabled.
- Restrict remote management access to trusted administration networks and approved operators only.
- Prefer disabling Telnet where operationally possible and use secure remote administration practices.
- Validate account and username policy handling after remediation, especially for usernames near or above 15 characters.
- Review CISA industrial control system recommended practices for defense-in-depth hardening.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-044-09 and the Siemens product security advisory referenced there. The advisory text states that affected devices truncate usernames longer than 15 characters when accessed via SSH or Telnet and that this could allow an attacker to compromise system integrity. The source also lists the remediation as V3.0.0 or later. Publication context in the supplied timeline shows the CVE/advisory was published on 2025-02-11 and revised on 2025-05-06 for typos.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-769027.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-769027.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.