PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-26889 Siemens CVE debrief

CVE-2024-26889 is a buffer overflow vulnerability in the Bluetooth hci_core component of the Linux kernel. The vulnerability was published on April 9, 2024, and affects Siemens SIMATIC S7-1500 TM MFP industrial control systems through their GNU/Linux subsystem. The issue carries a CVSS 3.1 score of 5.5 (MEDIUM severity) with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local attack vector, low attack complexity, low privileges required, no user interaction, and high availability impact with no confidentiality or integrity impact. The vulnerability stems from insufficient input validation in the Bluetooth host controller interface core, potentially allowing an attacker with local access to cause a denial of service condition. Siemens has not released a patch for this vulnerability as of the source document's last modification on May 14, 2026. The advisory has been updated multiple times since initial publication, with the most recent substantial update in September 2025 adding 51 additional CVEs to the same advisory document. Organizations should implement the available mitigations until a permanent fix becomes available.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Industrial control system operators, OT security teams, and asset owners deploying Siemens SIMATIC S7-1500 TM MFP with the GNU/Linux subsystem enabled should prioritize this vulnerability. Organizations in critical infrastructure sectors including manufacturing, energy, and water/wastewater that rely on these programmable logic controllers for automation should assess their exposure. Security architects designing defense-in-depth strategies for OT environments should incorporate these mitigations. Patch management teams should monitor for future Siemens updates addressing this kernel-level Bluetooth vulnerability.

Technical summary

CVE-2024-26889 is classified under CWE-20 (Improper Input Validation) and affects the Bluetooth host controller interface (HCI) core in the Linux kernel. The vulnerability allows a local attacker with low privileges to trigger a buffer overflow, resulting in a denial of service condition. The attack requires local access to the system with no user interaction needed. The vulnerability specifically impacts Siemens SIMATIC S7-1500 TM MFP devices that include a GNU/Linux subsystem, which exposes the underlying Linux kernel Bluetooth stack to potential exploitation. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) confirms this is primarily an availability-impacting vulnerability with no direct confidentiality or integrity consequences. As of the latest source update, Siemens has not released a software patch, leaving mitigation through access controls and trusted application enforcement as the primary defensive measures.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem on affected Siemens SIMATIC S7-1500 TM MFP devices to trusted personnel only
  • Implement application whitelisting to ensure only trusted applications are built and executed on the GNU/Linux subsystem
  • Monitor for anomalous Bluetooth-related activity or unexpected process crashes on affected systems
  • Apply defense-in-depth strategies for industrial control systems per CISA guidance
  • Subscribe to Siemens ProductCERT security advisories for notification when a patch becomes available

Evidence notes

Source: CISA CSAF advisory ICSA-24-102-01. The vulnerability description and CVSS vector are drawn directly from the source document. The affected product is explicitly identified as SIMATIC S7-1500 TM MFP - GNU/Linux subsystem. The remediation status of 'no fix available' is confirmed in the source remediations section. The advisory revision history shows multiple updates through September 2025, with CVE-2024-26889 present from the initial publication.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-26889 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-26889

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-26889 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26889

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.