PatchSiren cyber security CVE debrief
CVE-2024-46739 Siemens CVE debrief
A NULL pointer dereference vulnerability exists in the Linux kernel's uio_hv_generic driver, specifically in the hv_uio_rescind function. This flaw can lead to a kernel crash (denial of service) when triggered. The vulnerability affects Siemens industrial networking products running SINEC OS, including RUGGEDCOM RST2428P switches and multiple SCALANCE switch families. The issue is rated MEDIUM severity with a CVSS 3.1 score of 5.5, requiring local access and low privileges to exploit. Siemens has released firmware updates to address this vulnerability.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500, or SCALANCE XCM-/XRM-/XCH-/XRH-300 industrial switches in critical infrastructure, manufacturing, or utility environments. System administrators responsible for OT/ICS network security and availability should prioritize patching to prevent potential service disruptions.
Technical summary
The vulnerability resides in the uio_hv_generic Linux kernel driver, which provides userspace I/O support for Hyper-V devices. The hv_uio_rescind function fails to properly handle NULL pointer conditions, leading to a kernel NULL pointer dereference. This can be triggered to cause a denial of service through system crash. The flaw requires local access with low privileges and has no confidentiality or integrity impact, but high availability impact. The vulnerability affects Siemens industrial networking products that incorporate the vulnerable kernel component in their SINEC OS firmware.
Defensive priority
medium
Recommended defensive actions
- Apply vendor firmware updates: Update RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices to SINEC OS V3.2 or later. For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens ProductCERT
- Implement network segmentation for industrial control systems to limit local access
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor for anomalous system crashes or unexpected reboots on affected devices
- Review and apply Siemens security advisory SSA-355557 guidance for affected configurations
Evidence notes
Vulnerability disclosed via CISA ICS advisory ICSA-25-226-07, republished 2026-02-25 based on Siemens ProductCERT SSA-355557. Affects SINEC OS-based Siemens industrial switches. Kernel-level NULL pointer dereference in Hyper-V UIO driver component.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-46739 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-46739
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-46739 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-46739
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.