PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-38579 Siemens CVE debrief

CVE-2024-38579 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's Broadcom crypto driver (crypto: bcm). The flaw exists in the `spu2_dump_omd()` function where pointer arithmetic incorrectly increments by `ciph_key_len` instead of `hash_iv_len`, potentially causing out-of-bounds buffer access. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified this vulnerability as affecting multiple industrial networking products including the RUGGEDCOM RST2428P and SCALANCE X-family switches running SINEC OS. The vulnerability is classified with CWE-20 (Improper Input Validation). A vendor fix is available requiring update to SINEC OS V3.1 or later versions.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens industrial networking equipment including SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family, and RUGGEDCOM RST2428P switches. OT security teams, ICS asset owners, and critical infrastructure operators utilizing SINEC OS-based devices should prioritize patching to V3.1 or later.

Technical summary

The vulnerability resides in `spu2_dump_omd()` within the Broadcom SPU2 crypto driver. The function incorrectly calculates pointer advancement using `ciph_key_len` rather than `hash_iv_len` when processing authentication data. This miscalculation can cause the pointer to exceed allocated buffer boundaries, resulting in undefined behavior and potential kernel crash (local denial of service). The vulnerability requires local access with low privileges, limiting exploitability in properly segmented industrial networks.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided updates to SINEC OS V3.1 or later for affected SCALANCE and RUGGEDCOM products
  • Review and implement CISA ICS recommended practices for defense-in-depth strategies
  • Monitor Siemens ProductCERT advisory SSA-613116 for additional updates or clarifications
  • For products where patching is not immediately feasible, apply network segmentation and access controls to limit local attack vector exposure

Evidence notes

The vulnerability description indicates a classic pointer arithmetic error in kernel crypto code. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local attack vector with low attack complexity, requiring low privileges, with no user interaction, resulting in high availability impact but no confidentiality or integrity impact. This suggests a local denial-of-service condition rather than remote code execution.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-38579 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-38579

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-38579 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38579

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.