PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-47710 Siemens CVE debrief

CVE-2024-47710 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's sock_map subsystem, specifically within the sock_hash_free() function. The issue stems from the addition of a cond_resched() call intended to prevent CPU soft lockups when destroying maps with a large number of buckets. This vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens has identified affected products in its industrial networking portfolio, including RUGGEDCOM RST2428P and SCALANCE switch families. The vulnerability is exploitable locally with low attack complexity and low privileges required, resulting in high availability impact. Siemens has provided vendor fixes, with updates to V3.2 or later versions recommended for affected products.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens industrial networking infrastructure, particularly in critical infrastructure and OT environments. Security teams responsible for patch management of RUGGEDCOM and SCALANCE device fleets. ICS/SCADA security practitioners monitoring CISA advisories for third-party component vulnerabilities in industrial products.

Technical summary

The vulnerability exists in the Linux kernel's BPF sock_map subsystem. The sock_hash_free() function, which destroys hash-based socket maps, was modified to include a cond_resched() call to yield CPU time and prevent soft lockups when processing maps with large bucket counts. This modification introduced a vulnerability condition. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local attack vector requiring low privileges, with no confidentiality or integrity impact but high availability impact. The vulnerability affects Siemens industrial networking products running vulnerable Linux kernel versions, specifically RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, and SCALANCE XCM-/XRM-/XCH-/XRH-300 family. The advisory underwent three revision cycles after initial publication to correct affected product listings and clarify configuration requirements, with the most recent update on February 25, 2026.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided updates to V3.2 or later version for affected RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices per Siemens ProductCERT guidance
  • Review additional configuration guidance for SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family deployments
  • Monitor CISA ICS advisories for subsequent updates to affected product lists, as the advisory was revised multiple times (February 12, 24, and 25, 2026) to correct and clarify affected configurations
  • Implement defense-in-depth strategies for industrial control systems as recommended by CISA ICS security practices

Evidence notes

Vulnerability description sourced from CISA CSAF advisory ICSA-25-226-07. Affected products confirmed through Siemens ProductCERT SSA-355557. CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H indicates local attack vector with availability impact. Remediation guidance specifies V3.2 or later for RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family; SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family has vendor fix available with additional configuration guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-47710 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-47710

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-47710 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47710

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.