PatchSiren cyber security CVE debrief
CVE-2024-53194 Siemens CVE debrief
A use-after-free vulnerability in the Linux kernel's PCI subsystem affects Siemens industrial networking products. The flaw occurs during hot removal of USB4 docks when pci_slot and pci_bus references are improperly handled, potentially causing system crashes. The vulnerability is rated MEDIUM severity (CVSS 5.5) with local attack vector and low attack complexity. Affected products include RUGGEDCOM RST2428P switches and SCALANCE XC/XR/XCM/XRM/XCH/XRH family industrial Ethernet switches running SINEC OS. Siemens has released updates to address this issue.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P or SCALANCE industrial Ethernet switches in critical infrastructure, manufacturing, or utility environments where USB4 dock hot-removal scenarios may occur. Security teams responsible for OT/ICS asset management and patch coordination should prioritize this update. System integrators deploying SINEC OS-based infrastructure should verify update status before commissioning.
Technical summary
The vulnerability exists in the Linux kernel's PCI subsystem where improper reference counting between pci_slot and pci_bus structures leads to a use-after-free condition. When a USB4 dock undergoes hot removal, the pci_slot may access freed pci_bus memory, resulting in system instability or denial of service. The fix ensures pci_slot properly acquires a reference to pci_bus before access. This affects Siemens industrial products built on affected kernel versions, specifically RUGGEDCOM RST2428P and SCALANCE switch families running SINEC OS. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local exploitation with low complexity, requiring low privileges, with availability impact as the primary concern.
Defensive priority
medium
Recommended defensive actions
- Apply vendor updates to V3.2 or later for affected RUGGEDCOM and SCALANCE products per Siemens ProductCERT guidance
- Review CISA ICS recommended practices for defense-in-depth strategies for industrial control systems
- Monitor for additional vendor guidance on SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family configurations
- Implement network segmentation to limit exposure of affected industrial Ethernet switches
- Validate USB4 dock hot-removal procedures to minimize trigger conditions pending patch deployment
Evidence notes
CVE published 2025-08-12; CISA advisory ICSA-25-226-07 published same date. Siemens ProductCERT advisory SSA-355557 provides vendor fix details. Advisory modified 2026-02-25 with republication updates.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-53194 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-53194
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-53194 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-53194
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.