PatchSiren cyber security CVE debrief
CVE-2024-36005 Siemens CVE debrief
CVE-2024-36005 is a vulnerability in the Linux kernel's netfilter nf_tables subsystem, specifically affecting how the table dormant flag is handled during netdev release events. The flaw could allow a local attacker to cause a denial of service condition. The vulnerability has been assigned a CVSS 3.1 score of 5.5 (MEDIUM severity) with the vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local attack vector, low attack complexity, low privileges required, no user interaction, and high availability impact. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices. The vendor has provided a fix in version 3.1 or later. CISA published this advisory on August 12, 2025, with subsequent updates through February 25, 2026, including corrections to affected product listings and removal of rejected CVEs. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking infrastructure including SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family switches and RUGGEDCOM RST2428P devices. Critical infrastructure operators, manufacturing facilities, and utility providers utilizing these devices in industrial control system environments should prioritize assessment and patching.
Technical summary
The vulnerability exists in the Linux kernel's netfilter nf_tables subsystem where the table dormant flag is not properly honored during netdev release event processing. This flaw in the kernel's network packet filtering framework can be triggered by a local attacker with low privileges, resulting in a denial of service condition. The affected code path involves improper state handling when network devices are released, potentially causing system instability or crash. Siemens industrial networking products running SINEC OS versions prior to 3.1 incorporate the vulnerable kernel component. The fix ensures proper handling of the dormant flag during netdev release events, preventing the race condition or state inconsistency that leads to the availability impact.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided updates to SINEC OS version 3.1 or later for affected SCALANCE and RUGGEDCOM devices
- Verify device firmware versions against Siemens security advisory SSA-613116
- Implement network segmentation for industrial control systems per CISA recommended practices
- Monitor for anomalous local access attempts on affected devices
- Review and apply defense-in-depth strategies for industrial control environments
Evidence notes
Vulnerability description and CVSS scoring derived from CISA CSAF advisory ICSA-25-226-15. Affected products and remediation information confirmed through Siemens ProductCERT advisory SSA-613116. Timeline based on CISA advisory revision history showing initial publication 2025-08-12 and final republication 2026-02-25.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-36005 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-36005
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-36005 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-36005
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.