PatchSiren cyber security CVE debrief
CVE-2023-52868 Siemens CVE debrief
A string overflow vulnerability in the Linux kernel thermal subsystem was resolved upstream. Siemens ProductCERT has assessed this CVE as **Misinformed** for affected industrial network devices, indicating the vulnerability does not apply to the listed products as originally reported. The CISA ICS advisory ICSA-25-226-15 (published 2025-08-12, updated 2026-02-25) republishes Siemens guidance from SSA-613116. No CVSS score is assigned in the source corpus. No known exploitation or ransomware use is documented.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Operators of Siemens industrial network infrastructure (SCALANCE switches, RUGGEDCOM devices) running SINEC OS; security teams maintaining Linux-based OT environments; compliance auditors tracking CISA ICS advisory coverage.
Technical summary
The Linux kernel thermal core contained a potential string overflow condition that was resolved upstream. Siemens ProductCERT evaluated this vulnerability against industrial network infrastructure products (SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P) and determined the impact assessment to be 'Misinformed'—indicating the reported vulnerability does not apply to these products as initially categorized. The CISA ICS advisory ICSA-25-226-15, republished 2026-02-25, reflects this corrected assessment based on Siemens ProductCERT SSA-613116. No CVSS vector or score is provided in the source corpus.
Defensive priority
low
Recommended defensive actions
- Review Siemens ProductCERT advisory SSA-613116 for product-specific impact assessment
- Verify thermal subsystem configurations on Linux-based industrial devices per vendor guidance
- Apply vendor-provided firmware updates when available for affected product families
- Follow CISA ICS recommended practices for defense-in-depth strategies
Evidence notes
Source corpus indicates this CVE was assessed as 'Misinformed' impact for Siemens SCALANCE and RUGGEDCOM products. The Linux kernel fix description references a 'potential string overflow' in thermal core. No technical details of exploitability are provided in the source corpus.
Official resources
-
CVE-2023-52868 CVE record
CVE.org
-
CVE-2023-52868 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12