PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21694 Siemens CVE debrief

A softlockup vulnerability in the Linux kernel's fs/proc subsystem, specifically in the __read_vmcore function, affects Siemens industrial networking products running SINEC OS. The vulnerability can cause a denial-of-service condition through high availability impact when exploited locally with high privileges.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 4.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Organizations operating Siemens RUGGEDCOM RST2428P or SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500/XCM-/XRM-/XCH-/XRH-300 family industrial networking equipment in critical infrastructure environments, including utilities, transportation, and manufacturing sectors. Security teams responsible for OT/ICS asset management and patch deployment should prioritize assessment and remediation.

Technical summary

CVE-2025-21694 is a vulnerability in the Linux kernel's proc filesystem implementation, specifically within the __read_vmcore function. The flaw can trigger a softlockup condition, resulting in a denial-of-service with high availability impact. The vulnerability requires local access with high privileges to exploit, and has no impact on confidentiality or integrity. Affected products include Siemens RUGGEDCOM RST2428P switches and multiple SCALANCE industrial Ethernet switch families running SINEC OS. Siemens has released firmware updates to address this vulnerability.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided firmware updates to V3.2 or later for affected RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices
  • For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices, consult Siemens ProductCERT advisory SSA-355557 for specific configuration guidance and update instructions
  • Implement network segmentation for industrial control systems to limit local access to affected devices
  • Follow CISA ICS recommended practices for defense-in-depth strategies
  • Monitor device logs for unexpected softlockup or system hang conditions that may indicate exploitation attempts

Evidence notes

CISA published advisory ICSA-25-226-07 on August 12, 2025, identifying this CVE as affecting Siemens RUGGEDCOM and SCALANCE product families. The advisory was subsequently updated on February 25, 2026, to reflect corrections to the affected product list and clarifications on product configurations. Siemens ProductCERT issued advisory SSA-355557 providing vendor remediation guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21694 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21694

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21694 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21694

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.