PatchSiren cyber security CVE debrief
CVE-2024-53194 Siemens CVE debrief
A use-after-free vulnerability in the Linux kernel's PCI subsystem affects Siemens industrial networking products. The flaw occurs during hot removal of USB4 docks when pci_slot and pci_bus references are improperly handled, potentially causing system crashes. The vulnerability is rated MEDIUM severity (CVSS 5.5) with local attack vector and low attack complexity. Affected products include RUGGEDCOM RST2428P switches and SCALANCE XC/XR/XCM/XRM/XCH/XRH family industrial Ethernet switches running SINEC OS. Siemens has released updates to address this issue.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P or SCALANCE industrial Ethernet switches in critical infrastructure, manufacturing, or utility environments where USB4 dock hot-removal scenarios may occur. Security teams responsible for OT/ICS asset management and patch coordination should prioritize this update. System integrators deploying SINEC OS-based infrastructure should verify update status before commissioning.
Technical summary
The vulnerability exists in the Linux kernel's PCI subsystem where improper reference counting between pci_slot and pci_bus structures leads to a use-after-free condition. When a USB4 dock undergoes hot removal, the pci_slot may access freed pci_bus memory, resulting in system instability or denial of service. The fix ensures pci_slot properly acquires a reference to pci_bus before access. This affects Siemens industrial products built on affected kernel versions, specifically RUGGEDCOM RST2428P and SCALANCE switch families running SINEC OS. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local exploitation with low complexity, requiring low privileges, with availability impact as the primary concern.
Defensive priority
medium
Recommended defensive actions
- Apply vendor updates to V3.2 or later for affected RUGGEDCOM and SCALANCE products per Siemens ProductCERT guidance
- Review CISA ICS recommended practices for defense-in-depth strategies for industrial control systems
- Monitor for additional vendor guidance on SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configurations
- Implement network segmentation to limit exposure of affected industrial Ethernet switches
- Validate USB4 dock hot-removal procedures to minimize trigger conditions pending patch deployment
Evidence notes
CVE published 2025-08-12; CISA advisory ICSA-25-226-07 published same date. Siemens ProductCERT advisory SSA-355557 provides vendor fix details. Advisory modified 2026-02-25 with republication updates.
Official resources
-
CVE-2024-53194 CVE record
CVE.org
-
CVE-2024-53194 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
public