PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35965 Siemens CVE debrief

CVE-2024-35965 is a medium-severity vulnerability in the Linux kernel's Bluetooth L2CAP subsystem, specifically affecting the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP industrial control devices. The flaw involves improper validation of user input length in the setsockopt system call, which could lead to denial of service conditions. The vulnerability was published on April 9, 2024, and has been tracked in CISA's ICS advisory ICSA-24-102-01, which has undergone multiple revisions through September 2025 to incorporate additional related CVEs. Siemens has not released a patch for this issue; instead, they recommend operational mitigations including restricting interactive shell access to trusted personnel and ensuring only applications from trusted sources are built and executed on affected systems. The vulnerability requires local access with low privileges and has no impact on confidentiality or integrity, but can cause high availability impact through denial of service.

Vendor
Siemens
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-14
Advisory published
2024-04-09
Advisory updated
2026-05-14

Who should care

Organizations operating Siemens SIMATIC S7-1500 TM MFP devices in industrial environments, particularly those utilizing the GNU/Linux subsystem for custom applications. OT security teams, ICS asset owners, and system integrators responsible for maintaining availability of industrial control systems should prioritize access control mitigations.

Technical summary

The vulnerability exists in the Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) implementation within the Linux kernel. The setsockopt system call fails to validate user input length before copying data, potentially enabling a local attacker with low privileges to cause denial of service conditions. The flaw is classified under CWE-120 (Classic Buffer Overflow). The affected product is the GNU/Linux subsystem of Siemens SIMATIC S7-1500 TM MFP, an industrial automation device. No software patch is currently available from the vendor.

Defensive priority

medium

Recommended defensive actions

  • Restrict interactive shell access to the GNU/Linux subsystem on affected Siemens SIMATIC S7-1500 TM MFP devices to trusted personnel only
  • Implement application whitelisting to ensure only applications from trusted sources are built and executed on the GNU/Linux subsystem
  • Monitor for anomalous process activity or unexpected Bluetooth L2CAP socket operations on affected devices
  • Review and apply defense-in-depth strategies for industrial control systems as recommended by CISA
  • Subscribe to Siemens ProductCERT security advisories for notification when a patch becomes available

Evidence notes

Vulnerability description and affected product information derived from CISA CSAF advisory ICSA-24-102-01. CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H confirms local attack vector with availability impact only. Remediation status of 'none_available' and specific mitigation guidance extracted from source advisory remediations section.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35965 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35965

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35965 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35965

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-265688.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-265688.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.