PatchSiren cyber security CVE debrief
CVE-2024-35940 Siemens CVE debrief
A null pointer dereference vulnerability exists in the Linux kernel's pstore/zone subsystem within the psz_kmsg_read function. The flaw occurs when the function fails to validate a pointer before dereferencing it, potentially leading to a kernel crash and denial of service. This affects the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The vulnerability requires local access with low privileges and no user interaction, making it exploitable by authenticated users with shell access to the GNU/Linux subsystem. The CVSS 3.1 score of 5.5 reflects medium severity with high availability impact but no confidentiality or integrity impact.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Industrial control system operators using Siemens SIMATIC S7-1500 TM MFP with the GNU/Linux subsystem enabled; OT security teams managing embedded Linux environments; asset owners requiring high availability for manufacturing or process control systems
Technical summary
The vulnerability exists in fs/pstore/zone.c in the Linux kernel's persistent storage (pstore) zone implementation. The psz_kmsg_read function lacks a null pointer check before dereferencing a pointer, which can trigger a kernel oops or panic when reading from the pstore zone. This is classified as CWE-476 (NULL Pointer Dereference). The attack vector is local, requiring low privileges and no user interaction. The vulnerability specifically impacts availability with no direct confidentiality or integrity effects. Siemens has confirmed no fix is currently available as of the advisory publication.
Defensive priority
medium
Recommended defensive actions
- Restrict interactive shell access to the GNU/Linux subsystem to trusted personnel only
- Build and run applications only from trusted sources
- Monitor for anomalous process crashes or kernel panics on affected devices
- Apply vendor security updates when Siemens releases a fix for this vulnerability
- Implement network segmentation to limit access to industrial control devices
- Review and apply CISA ICS recommended practices for defense-in-depth strategies
Evidence notes
CVE published 2024-04-09 per official CVE record. CISA ICS advisory ICSA-24-102-01 published same date. Advisory last modified 2026-05-14 with multiple revision updates adding additional CVEs to the same Siemens product advisory. Source corpus indicates this vulnerability is tracked under CWE-476 (NULL Pointer Dereference).
Sources and references
Verified primary and authoritative sources
-
CVE-2024-35940 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-35940
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-35940 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35940
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.