PatchSiren cyber security CVE debrief
CVE-2024-46739 Siemens CVE debrief
A NULL pointer dereference vulnerability exists in the Linux kernel's uio_hv_generic driver, specifically in the hv_uio_rescind function. This flaw can lead to a kernel crash (denial of service) when triggered. The vulnerability affects Siemens industrial networking products running SINEC OS, including RUGGEDCOM RST2428P switches and multiple SCALANCE switch families. The issue is rated MEDIUM severity with a CVSS 3.1 score of 5.5, requiring local access and low privileges to exploit. Siemens has released firmware updates to address this vulnerability.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500, or SCALANCE XCM-/XRM-/XCH-/XRH-300 industrial switches in critical infrastructure, manufacturing, or utility environments. System administrators responsible for OT/ICS network security and availability should prioritize patching to prevent potential service disruptions.
Technical summary
The vulnerability resides in the uio_hv_generic Linux kernel driver, which provides userspace I/O support for Hyper-V devices. The hv_uio_rescind function fails to properly handle NULL pointer conditions, leading to a kernel NULL pointer dereference. This can be triggered to cause a denial of service through system crash. The flaw requires local access with low privileges and has no confidentiality or integrity impact, but high availability impact. The vulnerability affects Siemens industrial networking products that incorporate the vulnerable kernel component in their SINEC OS firmware.
Defensive priority
medium
Recommended defensive actions
- Apply vendor firmware updates: Update RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices to SINEC OS V3.2 or later. For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens ProductCERT
- Implement network segmentation for industrial control systems to limit local access
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor for anomalous system crashes or unexpected reboots on affected devices
- Review and apply Siemens security advisory SSA-355557 guidance for affected configurations
Evidence notes
Vulnerability disclosed via CISA ICS advisory ICSA-25-226-07, republished 2026-02-25 based on Siemens ProductCERT SSA-355557. Affects SINEC OS-based Siemens industrial switches. Kernel-level NULL pointer dereference in Hyper-V UIO driver component.
Official resources
-
CVE-2024-46739 CVE record
CVE.org
-
CVE-2024-46739 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12