PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35990 Siemens CVE debrief

A locking issue in the Xilinx DPDMA driver for Linux kernel could allow a local attacker to cause a denial of service condition. The vulnerability exists in the DMA subsystem's Xilinx DPDMA implementation where improper locking mechanisms may lead to race conditions or resource contention. A successful exploit requires local access with low privileges and no user interaction, resulting in high availability impact. The CVSS 3.1 vector indicates local attack vector with low attack complexity.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens SCALANCE and RUGGEDCOM industrial networking infrastructure, particularly those in critical infrastructure sectors with SINEC OS deployments. OT security teams responsible for patch management of industrial Ethernet switches and routers should prioritize this update.

Technical summary

The vulnerability resides in the Xilinx DPDMA (DisplayPort DMA) driver within the Linux kernel DMA subsystem. The issue involves improper locking that could be exploited by a local attacker with low privileges to trigger a denial of service condition. The attack requires no user interaction and has low attack complexity. The vulnerability affects Siemens industrial networking products including SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P when running SINEC OS versions prior to 3.1. The CVSS 3.1 score of 5.5 reflects medium severity with high availability impact but no confidentiality or integrity impact.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided firmware updates to V3.1 or later for affected Siemens SCALANCE and RUGGEDCOM devices per Siemens ProductCERT advisory
  • Review and implement CISA ICS recommended practices for industrial control systems defense in depth
  • Monitor Siemens ProductCERT security advisories for additional updates to SSA-613116
  • For environments where immediate patching is not feasible, apply network segmentation and access controls to limit local access to affected devices

Evidence notes

CISA ICS advisory ICSA-25-226-15 published 2025-08-12 identifies this vulnerability in Siemens industrial networking products running SINEC OS. The advisory was subsequently modified on 2026-02-25 to reflect updates based on Siemens ProductCERT SSA-613116. The vulnerability description indicates a fix for locking in the Xilinx DPDMA (DisplayPort DMA) driver. Siemens has issued a vendor fix recommending update to V3.1 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35990 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35990

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35990 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35990

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.