PatchSiren cyber security CVE debrief
CVE-2024-56587 Siemens CVE debrief
A race condition in the Linux kernel LED class subsystem allows NULL pointer dereference via concurrent access to led_cdev attributes. The vulnerability exists when Process A adds an HID device (triggering led_cdev addition) while Process B simultaneously accesses the led_cdev attribute, resulting in a NULL pointer dereference in brightness_show(). This is a local attack vector requiring low privileges with no user interaction, leading to high availability impact (system crash).
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Operators of Siemens industrial networking infrastructure including RUGGEDCOM RST2428P serial servers and SCALANCE managed switches running SINEC OS. Security teams managing OT environments with local user access or compromised low-privilege accounts.
Technical summary
The vulnerability resides in drivers/leds/led-class.c where brightness_show() lacks proper synchronization via led_cdev->led_access mutex during concurrent HID device registration and attribute access. The race window between led_cdev structure initialization and sysfs attribute exposure permits NULL dereference when Process B reads brightness before Process A completes device setup.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates: RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 families should update to V3.2 or later
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens ProductCERT SSA-355557 for specific configuration guidance and update paths
- Implement physical access controls to prevent local exploitation
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor for anomalous HID device attachment patterns on affected systems
Evidence notes
CISA ICS advisory ICSA-25-226-07 published 2025-08-12 identifies this CVE affecting Siemens industrial networking products running SINEC OS. The advisory was republished 2026-02-25 based on Siemens ProductCERT SSA-355557. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H confirms local attack vector with availability impact only.
Official resources
-
CVE-2024-56587 CVE record
CVE.org
-
CVE-2024-56587 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12