PatchSiren cyber security CVE debrief
CVE-2024-22365 Siemens CVE debrief
CVE-2024-22365 is a medium-severity denial-of-service issue in linux-pam affecting versions before 1.6.0. According to the NVD record, a local attacker with low privileges can trigger a blocked login process through mkfifo-related behavior because an openat call used for protect_dir lacks O_DIRECTORY. The practical impact is availability loss for authentication and login workflows, not data exposure or integrity compromise.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Administrators and security teams running linux-pam on Linux systems should care, especially where PAM is part of interactive login, privilege elevation, or remote access flows. Distribution maintainers and platform operators should also review whether their packaged linux-pam version is below 1.6.0 or whether the upstream patch has already been backported.
Technical summary
NVD lists linux-pam versions before 1.6.0 as vulnerable, with a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The record states that an attacker can cause a denial of service by blocking the login process via mkfifo-related behavior, because the openat call for protect_dir does not use O_DIRECTORY. The NVD record also maps the weakness to CWE-664 as a secondary classification, while the primary weakness is listed as CWE-noinfo.
Defensive priority
Medium
Recommended defensive actions
- Confirm whether any deployed linux-pam packages are earlier than 1.6.0.
- Upgrade to linux-pam 1.6.0 or later where possible.
- If immediate upgrade is not feasible, apply the upstream patch or a vendor backport referenced in the advisory record.
- Review systems where PAM-mediated logins are operationally critical, since the main impact is blocked authentication and login availability.
- Validate that downstream distribution advisories or package changelogs reflect the fix before and after deployment.
Evidence notes
The supplied NVD record publishes CVE-2024-22365 on 2024-02-06 and last modified it on 2026-05-12. The record cites an oss-security mailing list post from 2024-01-18, an upstream linux-pam commit, and the v1.6.0 release tag as reference material. The affected version range in NVD ends before 1.6.0. NVD assigns CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and lists the primary weakness as CWE-noinfo with CWE-664 as secondary.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-22365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-22365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-22365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.