PatchSiren cyber security CVE debrief
CVE-2024-40981 Siemens CVE debrief
CVE-2024-40981 is a vulnerability in the batman-adv (Better Approach To Mobile Ad-hoc Networking Advanced) kernel module, specifically within the `batadv_purge_orig_ref()` function. The issue involves empty buckets that can lead to soft lockups, causing system instability or denial of service conditions. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified this CVE as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. However, the CISA advisory marks the impact assessment as 'Misinformed,' suggesting potential discrepancies in the initial severity or scope evaluation. No CVSS score or severity rating is currently available. Organizations should monitor Siemens ProductCERT advisory SSA-355557 for definitive affected product lists and remediation guidance.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, or SCALANCE XCM-/XRM-/XCH-/XRH-300 family switches in mesh networking configurations. Industrial operators using batman-adv for wireless backhaul or ad-hoc network resilience in critical infrastructure environments.
Technical summary
The vulnerability exists in the `batadv_purge_orig_ref()` function of the batman-adv mesh networking kernel module. Empty hash buckets during originator table purging operations can trigger soft lockups, rendering the system unresponsive. This affects mesh networking functionality in embedded Linux systems, specifically Siemens industrial Ethernet switches running SINEC OS with batman-adv enabled. The condition represents a denial-of-service vector through resource exhaustion in kernel thread scheduling.
Defensive priority
medium
Recommended defensive actions
- Monitor Siemens ProductCERT advisory SSA-355557 for confirmed affected product lists and patch availability
- Review CISA ICS advisory ICSA-25-226-07 for updated impact assessment
- Assess network infrastructure for batman-adv usage in affected Siemens SCALANCE and RUGGEDCOM products
- Apply defense-in-depth controls per CISA ICS recommended practices pending vendor patches
- Subscribe to Siemens ProductCERT security advisories for SINEC OS updates
Evidence notes
The vulnerability description indicates a kernel-level issue in batman-adv's originator reference purging logic. The 'Misinformed' impact classification in the CISA CSAF data suggests the initial assessment may require correction. Siemens' SSA-355557 advisory is the authoritative source for affected product determination. The February 2026 revisions to the CISA advisory included significant corrections to affected product lists and removal of multiple rejected CVEs, indicating ongoing refinement of scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-40981 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-40981
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-40981 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-40981
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.