PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-46724 Siemens CVE debrief

CVE-2024-46724 is an out-of-bounds read vulnerability in the Linux kernel's drm/amdgpu driver, specifically affecting the df_v1_7_channel_number field. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. According to CISA's ICS advisory ICSA-25-226-07, this vulnerability was initially listed as affecting Siemens industrial networking products including the RUGGEDCOM RST2428P and SCALANCE families. However, subsequent advisory revisions indicate this CVE was **rejected and removed** from the affected products list. The February 2026 revision history explicitly states that CVE-2024-46724 was among rejected CVEs removed from the advisory. The threat assessment in the source material categorizes impact as 'Misinformed' for the listed product IDs. No CVSS score or severity rating is available in the provided source corpus. Organizations should verify current product security status through Siemens ProductCERT advisory SSA-355557 rather than relying on earlier versions of this advisory.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Siemens industrial networking equipment operators who may have reviewed earlier versions of ICSA-25-226-07; Linux kernel security practitioners tracking amdgpu driver vulnerabilities

Technical summary

Out-of-bounds read in df_v1_7_channel_number field of drm/amdgpu driver; CVE subsequently rejected and removed from affected product advisories

Defensive priority

low

Recommended defensive actions

  • Verify current security status through Siemens ProductCERT advisory SSA-355557
  • Review latest CISA ICS advisory ICSA-25-226-07 for updated product impact assessments
  • Apply standard defense-in-depth practices for industrial control systems per CISA guidance
  • Monitor Siemens security advisories for any future reclassification of this CVE

Evidence notes

Source indicates CVE was rejected and removed from affected products list in February 2026 revision; impact categorized as 'Misinformed' in threat data

Sources and references

Verified primary and authoritative sources

  • CVE-2024-46724 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-46724

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-46724 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-46724

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.