PatchSiren cyber security CVE debrief
CVE-2024-50561 Siemens CVE debrief
CVE-2024-50561 is a Siemens SCALANCE W700 issue in which affected devices do not properly sanitize filenames before upload. Siemens and CISA state this could let an authenticated remote attacker compromise system integrity. The advisory lists 19 affected SCALANCE WAB/WAM/WUB/WUM product variants and recommends updating to V3.0.0 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-02-11
- Advisory updated
- 2025-05-06
Who should care
Industrial control system operators, OT security teams, and Siemens SCALANCE administrators responsible for the listed WAB/WAM/WUB/WUM wireless access point and bridge models should prioritize this advisory, especially where file-upload features are exposed to trusted users or operational staff.
Technical summary
The advisory describes a filename-sanitization weakness in the upload path of affected Siemens SCALANCE devices. The security impact is limited to integrity according to the supplied CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N), while the narrative text says an authenticated remote attacker could compromise system integrity. Siemens’ remediation is to update affected products to version V3.0.0 or later.
Defensive priority
Medium
Recommended defensive actions
- Upgrade all affected SCALANCE WAB/WAM/WUB/WUM devices to V3.0.0 or later using Siemens' remediation guidance.
- Inventory the 19 listed product variants to confirm which devices are deployed and whether any are running vulnerable firmware.
- Review access to any upload functionality on these devices and limit it to only trusted administrative workflows.
- Monitor device logs and configuration management processes for unexpected file-upload activity or integrity changes.
- Track Siemens and CISA advisory updates for any additional remediation details or product-specific notes.
Evidence notes
Primary evidence comes from the Siemens advisory mirrored in CISA CSAF (ICSA-25-044-09 / SSA-769027), published on 2025-02-11 and revised on 2025-05-06 for typo fixes only. The source lists 19 affected Siemens SCALANCE product variants and a single remediation: update to V3.0.0 or later. The supplied enrichment marks this as not a Known Exploited Vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50561 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50561
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50561 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50561
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354112.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-354112.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.