PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-46780 Siemens CVE debrief

This CVE addresses a nilfs2 filesystem vulnerability in the Linux kernel where improper mutual exclusion when accessing superblock buffers in sysfs attribute show methods could lead to pointer dereferencing and memory access issues. The vulnerability stems from missing use of nilfs->ns_sem semaphore protection during these operations. Siemens has assessed this CVE as not affecting their listed industrial control system products, including the RUGGEDCOM RST2428P and SCALANCE switch families, based on their product security advisory SSA-355557. The CISA ICS advisory ICSA-25-226-07, which republished Siemens' assessment, was initially released on August 12, 2025, and most recently updated on February 25, 2026, to reflect corrections to affected product listings and removal of rejected CVEs. No CVSS score or severity rating is available in the source corpus. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Linux-based industrial control systems or embedded devices utilizing the nilfs2 filesystem should verify their exposure. Security teams managing Siemens RUGGEDCOM and SCALANCE product lines can reference vendor guidance indicating non-affected status. OT security practitioners should remain aware of kernel-level filesystem vulnerabilities as part of comprehensive asset inventory and vulnerability management programs.

Technical summary

The nilfs2 filesystem implementation in the Linux kernel contains a vulnerability where superblock buffers accessed through sysfs attribute show methods lack proper mutual exclusion via the nilfs->ns_sem semaphore. This omission can result in unsafe pointer dereferencing and memory access operations. The vulnerability is classified as a concurrency/synchronization issue in kernel filesystem code. Siemens has determined this CVE does not affect their industrial networking products.

Defensive priority

low

Recommended defensive actions

  • Verify nilfs2 filesystem is not deployed in embedded Linux environments within industrial control systems
  • Review kernel version and nilfs2 module usage in any Linux-based OT devices
  • Monitor vendor security advisories for affected product families if nilfs2 is in use
  • Apply standard defense-in-depth practices for ICS environments per CISA guidance

Evidence notes

Source corpus indicates Siemens ProductCERT assessed this CVE as 'Misinformed' impact (not affecting their products). CISA advisory ICSA-25-226-07 republishes Siemens SSA-355557. Revision history shows multiple updates: initial publication 2025-08-12, corrections 2026-02-12 and 2026-02-24, and republication 2026-02-25. No CVSS vector or score present in source.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-46780 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-46780

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-46780 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-46780

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.