PatchSiren cyber security CVE debrief
CVE-2024-35990 Siemens CVE debrief
A locking issue in the Xilinx DPDMA driver for Linux kernel could allow a local attacker to cause a denial of service condition. The vulnerability exists in the DMA subsystem's Xilinx DPDMA implementation where improper locking mechanisms may lead to race conditions or resource contention. A successful exploit requires local access with low privileges and no user interaction, resulting in high availability impact. The CVSS 3.1 vector indicates local attack vector with low attack complexity.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens SCALANCE and RUGGEDCOM industrial networking infrastructure, particularly those in critical infrastructure sectors with SINEC OS deployments. OT security teams responsible for patch management of industrial Ethernet switches and routers should prioritize this update.
Technical summary
The vulnerability resides in the Xilinx DPDMA (DisplayPort DMA) driver within the Linux kernel DMA subsystem. The issue involves improper locking that could be exploited by a local attacker with low privileges to trigger a denial of service condition. The attack requires no user interaction and has low attack complexity. The vulnerability affects Siemens industrial networking products including SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P when running SINEC OS versions prior to 3.1. The CVSS 3.1 score of 5.5 reflects medium severity with high availability impact but no confidentiality or integrity impact.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to V3.1 or later for affected Siemens SCALANCE and RUGGEDCOM devices per Siemens ProductCERT advisory
- Review and implement CISA ICS recommended practices for industrial control systems defense in depth
- Monitor Siemens ProductCERT security advisories for additional updates to SSA-613116
- For environments where immediate patching is not feasible, apply network segmentation and access controls to limit local access to affected devices
Evidence notes
CISA ICS advisory ICSA-25-226-15 published 2025-08-12 identifies this vulnerability in Siemens industrial networking products running SINEC OS. The advisory was subsequently modified on 2026-02-25 to reflect updates based on Siemens ProductCERT SSA-613116. The vulnerability description indicates a fix for locking in the Xilinx DPDMA (DisplayPort DMA) driver. Siemens has issued a vendor fix recommending update to V3.1 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-35990 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-35990
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-35990 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35990
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.