PatchSiren cyber security CVE debrief
CVE-2024-50602 Siemens CVE debrief
CVE-2024-50602 is a medium-severity vulnerability (CVSS 5.5) in libexpat before version 2.6.4, where the XML_ResumeParser function can crash when XML_StopParser is called to stop or suspend a parser that has not yet been started. This issue was published on August 12, 2025, and last modified on February 25, 2026. The vulnerability affects Siemens industrial networking products including the RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family. Siemens has issued vendor fixes, with updates to version 3.2 or later recommended for affected products. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SCALANCE and RUGGEDCOM industrial networking infrastructure, particularly those in critical infrastructure sectors relying on these devices for network segmentation and connectivity in industrial control system environments.
Technical summary
The vulnerability exists in libexpat versions prior to 2.6.4, specifically within the XML_ResumeParser function. The crash occurs when XML_StopParser is invoked to stop or suspend a parser instance that has not been started, resulting in a denial-of-service condition. The CVSS 3.1 score of 5.5 (MEDIUM) reflects a local attack vector with low attack complexity, no privileges required, but requiring user interaction. The confidentiality and integrity impacts are none, with high availability impact. Affected Siemens products include industrial Ethernet switches and routers used in operational technology environments.
Defensive priority
medium
Recommended defensive actions
- Update affected Siemens products to version 3.2 or later as specified in vendor advisories
- Review Siemens ProductCERT advisory SSA-355557 for specific product configuration guidance
- Apply defense-in-depth practices for industrial control systems per CISA recommendations
- Monitor for additional vendor updates regarding the SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configuration clarifications
Evidence notes
The vulnerability description and affected products are derived from CISA CSAF advisory ICSA-25-226-07, which references Siemens ProductCERT advisory SSA-355557. The CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H indicates a local attack vector requiring user interaction, with high availability impact.
Official resources
-
CVE-2024-50602 CVE record
CVE.org
-
CVE-2024-50602 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12