PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-49981 Siemens CVE debrief

A race condition in the Venus media driver (venus_remove) can trigger use-after-free memory corruption, leading to local denial of service. The vulnerability requires low attack complexity and local access with low privileges, but no user interaction. Siemens has confirmed this Linux kernel issue affects select industrial networking products running SINEC OS.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, or SCALANCE XCM-/XRM-/XCH-/XRH-300 family industrial networking equipment. Critical infrastructure operators and manufacturing environments relying on these devices for network segmentation and industrial communications should prioritize patching. Security teams responsible for OT/ICS asset management and vulnerability management programs.

Technical summary

The vulnerability exists in the Venus media driver subsystem of the Linux kernel. A race condition during the venus_remove operation can result in use-after-free memory access. This is a local vulnerability requiring low privileges but no user interaction. The primary impact is denial of service (availability) with no confidentiality or integrity impact per the CVSS vector. Affected Siemens products incorporate this vulnerable kernel component in their SINEC OS firmware.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided firmware updates to V3.2 or later for affected RUGGEDCOM and SCALANCE products per Siemens guidance
  • Review SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configuration to confirm affected status
  • Implement defense-in-depth controls for industrial control systems per CISA recommended practices
  • Monitor for anomalous system behavior or unexpected reboots on affected devices
  • Restrict local access to device management interfaces to authorized personnel only

Evidence notes

CISA published advisory ICSA-25-226-07 on 2025-08-12, with subsequent updates through 2026-02-25. The advisory references Siemens ProductCERT SSA-355557. CVSS 3.1 vector confirms local attack vector with availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-49981 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-49981

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-49981 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-49981

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.