PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-52868 Siemens CVE debrief

A string overflow vulnerability in the Linux kernel thermal subsystem was resolved upstream. Siemens ProductCERT has assessed this CVE as **Misinformed** for affected industrial network devices, indicating the vulnerability does not apply to the listed products as originally reported. The CISA ICS advisory ICSA-25-226-15 (published 2025-08-12, updated 2026-02-25) republishes Siemens guidance from SSA-613116. No CVSS score is assigned in the source corpus. No known exploitation or ransomware use is documented.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Operators of Siemens industrial network infrastructure (SCALANCE switches, RUGGEDCOM devices) running SINEC OS; security teams maintaining Linux-based OT environments; compliance auditors tracking CISA ICS advisory coverage.

Technical summary

The Linux kernel thermal core contained a potential string overflow condition that was resolved upstream. Siemens ProductCERT evaluated this vulnerability against industrial network infrastructure products (SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P) and determined the impact assessment to be 'Misinformed'—indicating the reported vulnerability does not apply to these products as initially categorized. The CISA ICS advisory ICSA-25-226-15, republished 2026-02-25, reflects this corrected assessment based on Siemens ProductCERT SSA-613116. No CVSS vector or score is provided in the source corpus.

Defensive priority

low

Recommended defensive actions

  • Review Siemens ProductCERT advisory SSA-613116 for product-specific impact assessment
  • Verify thermal subsystem configurations on Linux-based industrial devices per vendor guidance
  • Apply vendor-provided firmware updates when available for affected product families
  • Follow CISA ICS recommended practices for defense-in-depth strategies

Evidence notes

Source corpus indicates this CVE was assessed as 'Misinformed' impact for Siemens SCALANCE and RUGGEDCOM products. The Linux kernel fix description references a 'potential string overflow' in thermal core. No technical details of exploitability are provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-52868 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-52868

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-52868 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52868

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.