PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-49868 Siemens CVE debrief

A NULL pointer dereference vulnerability in the btrfs filesystem, triggered when a new transaction fails to start. The vulnerability was initially reported as affecting Siemens industrial networking products running SINEC OS, but subsequent analysis determined these products were not actually vulnerable. CISA and Siemens updated the advisory on 2026-02-25 to clarify affected configurations and remove rejected CVEs from the advisory. The vulnerability description contains a typographical error (trasacntion for transaction).

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Linux system administrators managing btrfs filesystems; industrial control system operators who reviewed earlier versions of the Siemens/CISA advisory; security teams tracking kernel-level filesystem vulnerabilities in operational technology environments

Technical summary

The vulnerability exists in the btrfs (B-tree filesystem) implementation in the Linux kernel. A NULL pointer dereference occurs when the filesystem fails to start a new transaction, potentially leading to system instability or denial of service. The vulnerability was initially associated with Siemens industrial networking products (RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, SCALANCE XCM-/XRM-/XCH-/XRH-300 family) running SINEC OS, but subsequent vendor analysis determined these products were not affected. The advisory was revised multiple times, with the final update on 2026-02-25 removing this CVE from the affected products list and clarifying the scope of impact.

Defensive priority

low

Recommended defensive actions

  • Verify btrfs filesystem usage in Linux kernel deployments
  • Apply kernel updates from distribution maintainers when available
  • Review Siemens ProductCERT SSA-355557 for definitive product impact statements
  • Monitor CISA ICS advisories for updates on industrial control system component vulnerabilities

Evidence notes

The source advisory ICSA-25-226-07 was published by CISA on 2025-08-12 and last modified on 2026-02-25. The advisory underwent multiple revisions, with the most significant update on 2026-02-25 clarifying that the SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family affected configuration was clarified and multiple CVEs were removed as rejected. The threat category in the source is marked as Misinformed for products CSAFPID-0006, CSAFPID-0002, and CSAFPID-0003.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-49868 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-49868

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-49868 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-49868

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.