PatchSiren cyber security CVE debrief
CVE-2024-42106 Siemens CVE debrief
This CVE addresses an uninitialized memory vulnerability in the Linux kernel's inet_diag subsystem. The fix initializes the pad field in struct inet_diag_req_v2, which was previously left uninitialized. This vulnerability could potentially lead to information disclosure or other undefined behavior when the uninitialized padding bytes are accessed. The issue affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices. The vulnerability is rated MEDIUM severity with a CVSS 3.1 score of 4.4, reflecting local attack vector, low attack complexity, and high privileges required, with availability impact as the primary concern. Siemens has released updates to address this issue in SINEC OS V3.1 and later versions.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking infrastructure, particularly those using RUGGEDCOM RST2428P or SCALANCE XC/XR series switches in critical infrastructure environments. OT security teams responsible for maintaining SINEC OS deployments should prioritize patching to V3.1 or later.
Technical summary
CVE-2024-42106 is an information disclosure vulnerability in the Linux kernel's inet_diag subsystem. The struct inet_diag_req_v2 contains a pad field that was not properly initialized, potentially leaking kernel stack memory or causing undefined behavior. The vulnerability is exploitable locally with high privileges required, limiting its practical attack surface. Siemens industrial networking products running SINEC OS are affected, including RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices. The fix ensures proper initialization of the pad field to prevent information leakage.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided updates to SINEC OS V3.1 or later for affected Siemens RUGGEDCOM and SCALANCE products
- Review and implement CISA ICS recommended practices for industrial control system security
- Monitor Siemens ProductCERT advisories for additional security updates
- Apply defense-in-depth strategies for industrial control systems as recommended by CISA
Evidence notes
The vulnerability was resolved in the Linux kernel by initializing the pad field in struct inet_diag_req_v2. The CISA ICS advisory ICSA-25-226-15, republished on 2026-02-25 based on Siemens ProductCERT SSA-613116, identifies affected Siemens products. The advisory was initially published on 2025-08-12 and underwent multiple revisions, including corrections to affected products list and removal of rejected CVEs. The CVSS vector indicates local attack vector with high privilege requirements, limiting exploitability.
Official resources
-
CVE-2024-42106 CVE record
CVE.org
-
CVE-2024-42106 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12