PatchSiren cyber security CVE debrief
CVE-2024-42095 Siemens CVE debrief
A vulnerability in the 8250_omap serial driver can trigger an erroneous timeout, potentially causing an interrupt storm. This condition may lead to system instability or denial of service on affected devices. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has assessed this CVE as not affecting their products, with the impact marked as 'Misinformed' in their advisory.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Linux-based industrial systems with OMAP serial interfaces should verify their exposure. Siemens customers can reference ProductCERT advisory SSA-355557 for definitive product impact status.
Technical summary
The 8250_omap serial driver in the Linux kernel contains a flaw where an erroneous timeout condition can be triggered, potentially resulting in an interrupt storm. This could cause system performance degradation or denial of service on systems utilizing this specific UART driver. The vulnerability is rated CVSS 5.5 (MEDIUM). Siemens has assessed that their products are not affected by this CVE, marking it as 'Misinformed' in their security advisory.
Defensive priority
low
Recommended defensive actions
- Verify serial driver configurations on Linux-based OT systems using 8250_omap driver
- Monitor for interrupt storm conditions on serial-dependent industrial devices
- Review Siemens ProductCERT advisory SSA-355557 for definitive product impact assessment
- Apply standard ICS defense-in-depth practices per CISA guidance
Evidence notes
The source advisory (ICSA-25-226-07) explicitly lists this CVE with impact category 'Misinformed' for all referenced product IDs (CSAFPID-0006, CSAFPID-0002, CSAFPID-0003), indicating Siemens products are not actually affected by this vulnerability despite initial inclusion. The CVE description describes a Linux kernel serial driver issue (8250_omap) that could cause interrupt storms.
Official resources
-
CVE-2024-42095 CVE record
CVE.org
-
CVE-2024-42095 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12