PatchSiren cyber security CVE debrief
CVE-2024-46780 Siemens CVE debrief
This CVE addresses a nilfs2 filesystem vulnerability in the Linux kernel where improper mutual exclusion when accessing superblock buffers in sysfs attribute show methods could lead to pointer dereferencing and memory access issues. The vulnerability stems from missing use of nilfs->ns_sem semaphore protection during these operations. Siemens has assessed this CVE as not affecting their listed industrial control system products, including the RUGGEDCOM RST2428P and SCALANCE switch families, based on their product security advisory SSA-355557. The CISA ICS advisory ICSA-25-226-07, which republished Siemens' assessment, was initially released on August 12, 2025, and most recently updated on February 25, 2026, to reflect corrections to affected product listings and removal of rejected CVEs. No CVSS score or severity rating is available in the source corpus. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Linux-based industrial control systems or embedded devices utilizing the nilfs2 filesystem should verify their exposure. Security teams managing Siemens RUGGEDCOM and SCALANCE product lines can reference vendor guidance indicating non-affected status. OT security practitioners should remain aware of kernel-level filesystem vulnerabilities as part of comprehensive asset inventory and vulnerability management programs.
Technical summary
The nilfs2 filesystem implementation in the Linux kernel contains a vulnerability where superblock buffers accessed through sysfs attribute show methods lack proper mutual exclusion via the nilfs->ns_sem semaphore. This omission can result in unsafe pointer dereferencing and memory access operations. The vulnerability is classified as a concurrency/synchronization issue in kernel filesystem code. Siemens has determined this CVE does not affect their industrial networking products.
Defensive priority
low
Recommended defensive actions
- Verify nilfs2 filesystem is not deployed in embedded Linux environments within industrial control systems
- Review kernel version and nilfs2 module usage in any Linux-based OT devices
- Monitor vendor security advisories for affected product families if nilfs2 is in use
- Apply standard defense-in-depth practices for ICS environments per CISA guidance
Evidence notes
Source corpus indicates Siemens ProductCERT assessed this CVE as 'Misinformed' impact (not affecting their products). CISA advisory ICSA-25-226-07 republishes Siemens SSA-355557. Revision history shows multiple updates: initial publication 2025-08-12, corrections 2026-02-12 and 2026-02-24, and republication 2026-02-25. No CVSS vector or score present in source.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-46780 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-46780
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-46780 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-46780
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.