PatchSiren cyber security CVE debrief
CVE-2024-56587 Siemens CVE debrief
A race condition in the Linux kernel LED class subsystem allows NULL pointer dereference via concurrent access to led_cdev attributes. The vulnerability exists when Process A adds an HID device (triggering led_cdev addition) while Process B simultaneously accesses the led_cdev attribute, resulting in a NULL pointer dereference in brightness_show(). This is a local attack vector requiring low privileges with no user interaction, leading to high availability impact (system crash).
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Operators of Siemens industrial networking infrastructure including RUGGEDCOM RST2428P serial servers and SCALANCE managed switches running SINEC OS. Security teams managing OT environments with local user access or compromised low-privilege accounts.
Technical summary
The vulnerability resides in drivers/leds/led-class.c where brightness_show() lacks proper synchronization via led_cdev->led_access mutex during concurrent HID device registration and attribute access. The race window between led_cdev structure initialization and sysfs attribute exposure permits NULL dereference when Process B reads brightness before Process A completes device setup.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates: RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 families should update to V3.2 or later
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens ProductCERT SSA-355557 for specific configuration guidance and update paths
- Implement physical access controls to prevent local exploitation
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor for anomalous HID device attachment patterns on affected systems
Evidence notes
CISA ICS advisory ICSA-25-226-07 published 2025-08-12 identifies this CVE affecting Siemens industrial networking products running SINEC OS. The advisory was republished 2026-02-25 based on Siemens ProductCERT SSA-355557. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H confirms local attack vector with availability impact only.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-56587 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-56587
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-56587 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-56587
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.