PatchSiren cyber security CVE debrief
CVE-2024-26805 Siemens CVE debrief
This CVE addresses a kernel information leak after free vulnerability in the Linux kernel's netlink subsystem, specifically within the skb_datagram_iter function. The vulnerability was resolved with a fix to prevent information disclosure from freed memory. Siemens has identified this CVE as affecting multiple industrial networking product families including RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices running SINEC OS. The CISA advisory ICSA-25-226-15, published August 12, 2025 and most recently updated February 25, 2026, incorporates Siemens ProductCERT advisory SSA-613116. The advisory has undergone multiple revisions, including corrections to affected product listings and removal of rejected CVEs in February 2026. Organizations should consult vendor guidance for patch availability and apply defense-in-depth strategies for industrial control systems.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SINEC OS-based industrial networking infrastructure, including critical infrastructure operators using SCALANCE and RUGGEDCOM devices. OT security teams responsible for patch management in industrial environments.
Technical summary
The vulnerability exists in the Linux kernel's netlink implementation where skb_datagram_iter could access freed memory, resulting in kernel information leakage. This affects Siemens industrial networking products running SINEC OS, including RUGGEDCOM RST2428P and SCALANCE XC/XR series switches. The fix resolves the use-after-free condition to prevent information disclosure.
Defensive priority
medium
Recommended defensive actions
- Review Siemens ProductCERT advisory SSA-613116 for affected product versions and patch availability
- Apply vendor-provided firmware updates for SINEC OS when available
- Implement network segmentation for industrial control systems per CISA recommended practices
- Monitor CISA ICS advisories for additional guidance on affected Siemens products
Evidence notes
Vulnerability description sourced from CVE record and CISA CSAF advisory ICSA-25-226-15. Siemens ProductCERT SSA-613116 identified as canonical source. Advisory revision history shows multiple updates through February 25, 2026, including product list corrections and CVE removals.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-26805 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-26805
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-26805 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26805
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.