PatchSiren cyber security CVE debrief
CVE-2024-39502 Siemens CVE debrief
CVE-2024-39502 is a use-after-free vulnerability in the Linux kernel's ionic network driver, specifically affecting the NAPI (New API) polling mechanism. The flaw occurs when `ionic_qcq_enable()` incorrectly enables NAPI for queues that were previously unregistered via `netif_napi_del()`, because the `.poll` pointer is not reset to NULL upon deletion. This can lead to calling `napi_enable()` on an unregistered queue, potentially causing system instability or denial of service conditions. The vulnerability has a CVSS score of 5.5 (MEDIUM) and was published on August 12, 2025. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. CISA and Siemens have coordinated on this advisory, with the most recent update on February 25, 2026, reflecting republication based on Siemens ProductCERT guidance. No known exploitation in the wild has been reported, and this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking equipment including RUGGEDCOM RST2428P and SCALANCE X-family switches in critical infrastructure environments. System administrators responsible for Linux-based industrial control systems using ionic-compatible network hardware. Security teams monitoring OT/ICS environments for kernel-level vulnerabilities that could impact network availability.
Technical summary
The ionic network driver in the Linux kernel contains a use-after-free condition in its queue configuration management. When network queues are started, `netif_napi_add()` and `napi_enable()` are called for active queues. The `ionic_qcq_enable()` function uses the `.poll` pointer to determine which queues should have NAPI enabled, expecting NULL for unused queues. However, when `netif_napi_del()` unregisters a queue's NAPI, it does not reset the `.poll` pointer to NULL. Consequently, `ionic_qcq_enable()` cannot distinguish between never-registered queues and previously-registered-then-deleted queues, leading to `napi_enable()` being called on unregistered NAPI structures. This improper state management can result in memory corruption or system crashes.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates for affected Siemens SCALANCE and RUGGEDCOM products when available
- Monitor Siemens ProductCERT security advisories for patch availability
- Implement network segmentation for industrial control systems to limit exposure
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Review and update incident response procedures for industrial network infrastructure
Evidence notes
Vulnerability description derived from CISA CSAF advisory ICSA-25-226-07 and Siemens ProductCERT SSA-355557. The technical root cause involves improper state tracking in the ionic driver's NAPI lifecycle management. Affected products confirmed through Siemens CSAF product tree with high confidence. Timeline reflects CISA republication on 2026-02-25 based on Siemens advisory updates.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-39502 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-39502
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-39502 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-39502
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.