PatchSiren cyber security CVE debrief
CVE-2024-50198 Siemens CVE debrief
A NULL pointer dereference vulnerability exists in the Linux kernel's Industrial I/O (IIO) light sensor driver for the VEML6030 ambient light sensor. The flaw resides in the `in_illuminance_period_available_show` function, which incorrectly retrieves the IIO device structure from an embedded device pointer. The function receives a `dev` pointer referencing the device embedded within the IIO device rather than the I2C client device. Without using `dev_to_iio_dev()` to properly access the correct data structure, `indio_dev` receives a NULL assignment. This results in a segmentation fault on every attempt to read the affected sysfs attribute. The vulnerability is classified as a NULL pointer dereference (CWE-476) with medium severity. Local attackers with low privileges can trigger denial of service conditions by attempting to read the illuminance period available attribute. The issue affects Siemens industrial networking products running SINEC OS that incorporate the vulnerable kernel driver, specifically the RUGGEDCOM RST2428P and SCALANCE XC/XR/XCM/XRM/XCH/XRH product families.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking infrastructure including RUGGEDCOM RST2428P switches and SCALANCE XC/XR/XCM/XRM/XCH/XRH product families running SINEC OS. System administrators responsible for Linux-based industrial control systems with ambient light sensor hardware. Security teams monitoring kernel-level vulnerabilities in embedded industrial devices. Organizations subject to NERC CIP or other industrial cybersecurity frameworks requiring timely vulnerability remediation.
Technical summary
The vulnerability exists in the `in_illuminance_period_available_show` function within the Linux kernel's IIO light sensor driver for the VEML6030 ambient light sensor. The function incorrectly handles device pointer retrieval: the received `dev` pointer references the device embedded in the IIO device structure, not the I2C client device as assumed. The proper `dev_to_iio_dev()` macro must be used to correctly access the IIO device data. The current implementation assigns NULL to `indio_dev`, causing a segmentation fault on every read attempt of the `in_illuminance_period_available` sysfs attribute. This is a classic NULL pointer dereference (CWE-476) resulting in denial of service through system crash. The vulnerability requires local access with low privileges but no user interaction, making it exploitable by authenticated local users or processes on affected systems.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to address the underlying kernel vulnerability in affected Siemens industrial networking products
- For RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices, update to SINEC OS V3.2 or later
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices, consult Siemens ProductCERT advisory SSA-355557 for specific configuration guidance and update to V3.2 or later
- Restrict local access to industrial control systems and implement defense-in-depth strategies per CISA ICS recommended practices
- Monitor for anomalous system crashes or segmentation faults in IIO subsystem logs that may indicate exploitation attempts
- Review and apply Siemens security advisories for SINEC OS and related industrial networking products on a regular basis
Evidence notes
The vulnerability description is sourced from CISA ICS Advisory ICSA-25-226-07, which republishes Siemens ProductCERT advisory SSA-355557. The technical details indicate this is a Linux kernel driver bug in the veml6030 ambient light sensor IIO driver. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) confirms local attack vector with low attack complexity and low privileges required, resulting in high availability impact. The vulnerability was initially published on 2025-08-12 and last modified on 2026-02-25 when CISA republished based on updated Siemens advisory information.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50198 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50198
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50198 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50198
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.