PatchSiren cyber security CVE debrief
CVE-2024-50602 Siemens CVE debrief
CVE-2024-50602 is a medium-severity vulnerability (CVSS 5.5) in libexpat before version 2.6.4, where the XML_ResumeParser function can crash when XML_StopParser is called to stop or suspend a parser that has not yet been started. This issue was published on August 12, 2025, and last modified on February 25, 2026. The vulnerability affects Siemens industrial networking products including the RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family. Siemens has issued vendor fixes, with updates to version 3.2 or later recommended for affected products. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SCALANCE and RUGGEDCOM industrial networking infrastructure, particularly those in critical infrastructure sectors relying on these devices for network segmentation and connectivity in industrial control system environments.
Technical summary
The vulnerability exists in libexpat versions prior to 2.6.4, specifically within the XML_ResumeParser function. The crash occurs when XML_StopParser is invoked to stop or suspend a parser instance that has not been started, resulting in a denial-of-service condition. The CVSS 3.1 score of 5.5 (MEDIUM) reflects a local attack vector with low attack complexity, no privileges required, but requiring user interaction. The confidentiality and integrity impacts are none, with high availability impact. Affected Siemens products include industrial Ethernet switches and routers used in operational technology environments.
Defensive priority
medium
Recommended defensive actions
- Update affected Siemens products to version 3.2 or later as specified in vendor advisories
- Review Siemens ProductCERT advisory SSA-355557 for specific product configuration guidance
- Apply defense-in-depth practices for industrial control systems per CISA recommendations
- Monitor for additional vendor updates regarding the SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configuration clarifications
Evidence notes
The vulnerability description and affected products are derived from CISA CSAF advisory ICSA-25-226-07, which references Siemens ProductCERT advisory SSA-355557. The CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H indicates a local attack vector requiring user interaction, with high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.