PatchSiren cyber security CVE debrief
CVE-2024-26593 Siemens CVE debrief
A vulnerability in the Linux kernel's i2c i801 driver affecting block process call transactions has been identified in Siemens industrial networking products. The issue was resolved in the upstream Linux kernel. Siemens has assessed the impact as 'Misinformed' for affected products, indicating the vulnerability does not pose a practical security risk to the identified product lines. The advisory was initially published on August 12, 2025, with subsequent revisions through February 25, 2026, to correct affected product listings and remove rejected CVEs. No CVSS score has been assigned by the source advisory.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM and SCALANCE industrial networking equipment, particularly those in critical infrastructure sectors with OT/ICS environments. Security teams responsible for vulnerability management in industrial control systems should monitor this advisory for completeness, though the assessed impact suggests limited practical concern.
Technical summary
The vulnerability exists in the Linux kernel's i2c i801 driver, specifically in block process call transactions. The issue has been resolved in the upstream Linux kernel. Siemens products incorporating this component have been assessed with 'Misinformed' impact, indicating the theoretical vulnerability does not present a practical security concern for the identified product configurations. The affected product family includes RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices running SINEC OS.
Defensive priority
low
Recommended defensive actions
- Verify SINEC OS and SCALANCE device firmware versions against Siemens security advisory SSA-613116
- Apply vendor-recommended updates when available per Siemens ProductCERT guidance
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor Siemens ProductCERT and CISA ICS advisories for future updates to this vulnerability
Evidence notes
Source: CISA CSAF advisory ICSA-25-226-15, derived from Siemens ProductCERT SSA-613116. Impact assessment: 'Misinformed' per source threats data. Vendor confirmed: Siemens. Affected product: RUGGEDCOM RST2428P (6GK6242-6PA00). Resolution: Fixed in Linux kernel i2c i801 driver.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-26593 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-26593
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-26593 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26593
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.