PatchSiren cyber security CVE debrief
CVE-2024-26702 Siemens CVE debrief
A boundary check vulnerability in the Linux kernel's RM3100 magnetometer driver (iio: magnetometer: rm3100) was resolved by adding validation for values read from RM3100_REG_TMRC. The vulnerability involves insufficient boundary checking of register values that could lead to undefined behavior. Siemens has assessed this CVE as 'Misinformed' for affected industrial networking products including the RUGGEDCOM RST2428P and SCALANCE X-family devices, indicating the vulnerability does not actually affect these products as initially reported. The issue was originally published on August 12, 2025, with subsequent advisory updates through February 25, 2026, correcting product impact assessments.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking equipment (RUGGEDCOM RST2428P, SCALANCE X-family) should verify their exposure assessment; Linux kernel maintainers and embedded systems developers using the RM3100 magnetometer driver should ensure boundary checks are implemented
Technical summary
The vulnerability exists in the Linux kernel's Industrial I/O (IIO) subsystem, specifically the RM3100 magnetometer driver. The fix adds boundary checking for values read from the RM3100_REG_TMRC register. Without proper bounds validation, register values could potentially cause out-of-bounds access or other undefined behavior. The RM3100 is a 3-axis magnetometer used in various sensing applications. Siemens has determined this vulnerability does not actually affect their reported product lines (RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family), classifying the reported impact as 'Misinformed' in their security advisory.
Defensive priority
low
Recommended defensive actions
- Verify current SINEC OS version on affected Siemens devices; versions 3.1 and above are supported
- Review Siemens ProductCERT SSA-613116 for definitive product impact assessment
- Apply standard defense-in-depth practices for industrial control systems per CISA guidance
- Monitor CISA ICS advisories for any future corrections to this vulnerability's scope
Evidence notes
CVE published 2025-08-12; modified 2026-02-25. Siemens ProductCERT SSA-613116 and CISA ICSA-25-226-15 both classify impact as 'Misinformed' for affected product lines. Advisory revision history shows corrections to affected products list on 2026-02-12 and 2026-02-24.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-26702 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-26702
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-26702 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26702
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.