PatchSiren cyber security CVE debrief
CVE-2024-49983 Siemens CVE debrief
This CVE addresses a double-free vulnerability in the Linux ext4 filesystem, specifically within the ext4_ext_replay_update_ex() function. The flaw occurs when ext4_force_split_extent_at() is called: the 'ppath' variable is updated, but the original 'path' variable is freed instead, creating conditions for a double-free memory corruption. This vulnerability has been identified as affecting Siemens industrial networking products that incorporate the vulnerable Linux kernel component.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, or SCALANCE XCM-/XRM-/XCH-/XRH-300 family industrial networking equipment in operational technology (OT) environments. System administrators responsible for firmware maintenance of Siemens industrial Ethernet switches and ruggedized networking infrastructure.
Technical summary
The vulnerability exists in the ext4 filesystem's extent handling code. During journal replay operations (ext4_ext_replay_update_ex), when extent splitting is forced via ext4_force_split_extent_at(), the code incorrectly manages path pointers: 'ppath' receives the updated pointer while 'path' is incorrectly freed. This pointer confusion can lead to use-after-free or double-free conditions, potentially causing kernel crashes or memory corruption. The CVSS score of 5.5 (MEDIUM) reflects the local attack vector requirement and high availability impact with no confidentiality or integrity impact.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to V3.2 or later for affected RUGGEDCOM and SCALANCE products per Siemens ProductCERT guidance
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens support documentation for specific configuration guidance
- Implement network segmentation for industrial control systems to limit local access prerequisites
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor Siemens ProductCERT advisories for additional affected product clarifications
Evidence notes
The vulnerability description is sourced from CISA CSAF advisory ICSA-25-226-07, which was republished on 2026-02-25 based on Siemens ProductCERT SSA-355557. The advisory underwent multiple revisions, with significant updates on 2026-02-12 (correcting affected products list), 2026-02-24 (clarifying SCALANCE family configurations and removing rejected CVEs), and 2026-02-25 (CISA republication). The CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H indicates local attack vector with low complexity, requiring low privileges, resulting in high availability impact only.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-49983 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-49983
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-49983 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-49983
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.