PatchSiren cyber security CVE debrief
CVE-2024-56698 Siemens CVE debrief
A vulnerability in the Linux kernel USB DWC3 gadget driver affects Siemens industrial networking products. The flaw involves improper handling of scatter-gather (SG) entries in USB gadget requests, where the num_queued_sgs counter is decremented on completion but not properly maintained for partially completed requests, leading to potential state corruption.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500, or SCALANCE XCM-/XRM-/XCH-/XRH-300 industrial networking equipment in operational technology (OT) environments. System integrators and asset owners in critical infrastructure sectors including energy, manufacturing, and transportation.
Technical summary
The vulnerability exists in the DesignWare USB3 (DWC3) gadget driver within the Linux kernel. The dwc3_request structure tracks queued scatter-gather entries via num_queued_sgs, which is decremented upon request completion. When a request is partially completed, this counter no longer accurately reflects the total number of queued SG entries, potentially causing incorrect loop iterations or state management in subsequent operations. This is classified as CWE-20 (Improper Input Validation). The CVSS 3.1 vector indicates local attack vector, low attack complexity, low privileges required, no user interaction, with high availability impact (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates: update RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family to V3.2 or later per Siemens guidance
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, consult Siemens ProductCERT advisory SSA-355557 for specific configuration guidance
- Implement network segmentation for industrial control systems to limit exposure of affected devices
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor Siemens ProductCERT and CISA ICS advisories for additional updates
Evidence notes
CVE published 2025-08-12; CISA advisory ICSA-25-226-07 published same date; advisory modified 2026-02-25 with republication based on Siemens ProductCERT SSA-355557. CVSS 5.5 (MEDIUM) per source. Not in CISA KEV.
Official resources
-
CVE-2024-56698 CVE record
CVE.org
-
CVE-2024-56698 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12