PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-52623 Siemens CVE debrief

A vulnerability in the Linux kernel's SUNRPC subsystem that triggered suspicious RCU (Read-Copy-Update) usage warnings has been resolved. The issue was addressed in the kernel and affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA published this advisory on August 12, 2025, with subsequent updates through February 2026 to correct affected product listings and remove rejected CVEs. The vulnerability is classified as 'Misinformed' impact per the source advisory. No CVSS score or severity rating is available in the source data.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens industrial networking infrastructure, particularly those using RUGGEDCOM RST2428P or SCALANCE X-family switches with SINEC OS. OT security teams managing critical infrastructure networks, manufacturing environments, and utility substations where these devices are commonly deployed.

Technical summary

The vulnerability involves improper RCU (Read-Copy-Update) usage in the Linux kernel's SUNRPC (Sun Remote Procedure Call) subsystem, which is used for NFS and other network filesystem operations. RCU is a synchronization mechanism that allows read-heavy workloads to proceed without locking. Suspicious RCU usage warnings typically indicate potential race conditions or use-after-free scenarios that could lead to system instability or memory corruption. The fix was committed to the Linux kernel upstream. Siemens SINEC OS, which is based on Linux, incorporated this fix. The affected products include RUGGEDCOM RST2428P switches and multiple SCALANCE X-family industrial Ethernet switches (XC-300/XR-300/XC-400/XR-500WG/XR-500 and XCM-/XRM-/XCH-/XRH-300 families).

Defensive priority

medium

Recommended defensive actions

  • Review Siemens ProductCERT advisory SSA-613116 for detailed product impact and patch information
  • Verify SINEC OS version on affected SCALANCE and RUGGEDCOM devices
  • Apply vendor-provided firmware updates for SINEC OS 3.1 and later versions
  • Follow CISA ICS recommended practices for defense-in-depth strategies
  • Monitor CISA ICS advisories for additional updates to ICSA-25-226-15

Evidence notes

CVE published 2025-08-12; modified 2026-02-25. Source advisory ICSA-25-226-15 from CISA CSAF. Siemens ProductCERT advisory SSA-613116 is the canonical source. Advisory underwent four revisions, with significant updates on 2026-02-12 (product list corrections), 2026-02-24 (removed rejected CVEs), and 2026-02-25 (CISA republication).

Sources and references

Verified primary and authoritative sources

  • CVE-2023-52623 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-52623

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-52623 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52623

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.