PatchSiren cyber security CVE debrief
CVE-2025-21694 Siemens CVE debrief
A softlockup vulnerability in the Linux kernel's fs/proc subsystem, specifically in the __read_vmcore function, affects Siemens industrial networking products running SINEC OS. The vulnerability can cause a denial-of-service condition through high availability impact when exploited locally with high privileges.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- MEDIUM 4.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens RUGGEDCOM RST2428P or SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500/XCM-/XRM-/XCH-/XRH-300 family industrial networking equipment in critical infrastructure environments, including utilities, transportation, and manufacturing sectors. Security teams responsible for OT/ICS asset management and patch deployment should prioritize assessment and remediation.
Technical summary
CVE-2025-21694 is a vulnerability in the Linux kernel's proc filesystem implementation, specifically within the __read_vmcore function. The flaw can trigger a softlockup condition, resulting in a denial-of-service with high availability impact. The vulnerability requires local access with high privileges to exploit, and has no impact on confidentiality or integrity. Affected products include Siemens RUGGEDCOM RST2428P switches and multiple SCALANCE industrial Ethernet switch families running SINEC OS. Siemens has released firmware updates to address this vulnerability.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to V3.2 or later for affected RUGGEDCOM RST2428P and SCALANCE XCM-/XRM-/XCH-/XRH-300 family devices
- For SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family devices, consult Siemens ProductCERT advisory SSA-355557 for specific configuration guidance and update instructions
- Implement network segmentation for industrial control systems to limit local access to affected devices
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Monitor device logs for unexpected softlockup or system hang conditions that may indicate exploitation attempts
Evidence notes
CISA published advisory ICSA-25-226-07 on August 12, 2025, identifying this CVE as affecting Siemens RUGGEDCOM and SCALANCE product families. The advisory was subsequently updated on February 25, 2026, to reflect corrections to the affected product list and clarifications on product configurations. Siemens ProductCERT issued advisory SSA-355557 providing vendor remediation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21694 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21694
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21694 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21694
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-355557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-355557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.