PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-50602 Siemens CVE debrief

CVE-2024-50602 is a medium-severity vulnerability (CVSS 5.5) in libexpat before version 2.6.4, where the XML_ResumeParser function can crash when XML_StopParser is called to stop or suspend a parser that has not yet been started. This issue was published on August 12, 2025, and last modified on February 25, 2026. The vulnerability affects Siemens industrial networking products including the RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family. Siemens has issued vendor fixes, with updates to version 3.2 or later recommended for affected products. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens SCALANCE and RUGGEDCOM industrial networking infrastructure, particularly those in critical infrastructure sectors relying on these devices for network segmentation and connectivity in industrial control system environments.

Technical summary

The vulnerability exists in libexpat versions prior to 2.6.4, specifically within the XML_ResumeParser function. The crash occurs when XML_StopParser is invoked to stop or suspend a parser instance that has not been started, resulting in a denial-of-service condition. The CVSS 3.1 score of 5.5 (MEDIUM) reflects a local attack vector with low attack complexity, no privileges required, but requiring user interaction. The confidentiality and integrity impacts are none, with high availability impact. Affected Siemens products include industrial Ethernet switches and routers used in operational technology environments.

Defensive priority

medium

Recommended defensive actions

  • Update affected Siemens products to version 3.2 or later as specified in vendor advisories
  • Review Siemens ProductCERT advisory SSA-355557 for specific product configuration guidance
  • Apply defense-in-depth practices for industrial control systems per CISA recommendations
  • Monitor for additional vendor updates regarding the SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configuration clarifications

Evidence notes

The vulnerability description and affected products are derived from CISA CSAF advisory ICSA-25-226-07, which references Siemens ProductCERT advisory SSA-355557. The CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H indicates a local attack vector requiring user interaction, with high availability impact.

Official resources

2025-08-12