PatchSiren

siemens CVE debriefs · Page 15

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56698

A vulnerability in the Linux kernel USB DWC3 gadget driver affects Siemens industrial networking products. The flaw involves improper handling of scatter-gather (SG) entries in USB gadget requests, where the num_queued_sgs counter is decremented on completion but not properly maintained for partially completed requests, leading to potential state corruption.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56691

CVE-2024-56691 is a medium-severity vulnerability (CVSS 5.5) affecting the Intel SoC PMIC BXTWC driver in the Linux kernel. The flaw stems from implementation issues in converting the driver to use IRQ domain hierarchy for USB Type-C device handling. While the design approach was sound, the execution contained inherited flaws that could lead to denial of service conditions. Siemens has identified this vul [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56690

A vulnerability in the Linux kernel's parallel crypto processing layer (pcrypt) affects Siemens industrial network devices running SINEC OS. When the padata_do_parallel() function returns -EBUSY, the crypto layer is not properly invoked, potentially causing cryptographic operations to fail or behave unpredictably. This local vulnerability requires low privileges to exploit and can result in high availabil [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56681

CVE-2024-56681 is a medium-severity vulnerability (CVSS 5.5) affecting Siemens industrial networking products, specifically the RUGGEDCOM RST2428P and SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 and XCM-/XRM-/XCH-/XRH-300 families. The vulnerability exists in the Linux kernel's crypto subsystem, specifically in the Broadcom (bcm) crypto driver, where the ahash_hmac_init function fails to properly check [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56670

A race condition in the Linux kernel USB gadget serial driver (u_serial) can cause a null pointer dereference crash when concurrent open and disconnect operations occur. The vulnerability exists in the gs_start_io function where the port->port_usb pointer may be set to NULL by a disconnecting thread while another thread attempts to use it. This affects Siemens industrial networking products running SINEC [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56659

A vulnerability in the Linux kernel's LAPB (Link Access Procedure, Balanced) networking code creates uncertainty about 802.1Q VLAN readiness, potentially causing system crashes. The issue affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and multiple SCALANCE switch families. Siemens has released firmware updates to address this vulnerability.

HIGH Siemens CVE published 2025-08-12

CVE-2024-56650

CVE-2024-56650 is a HIGH severity vulnerability (CVSS 7.8) in the Linux kernel's netfilter x_tables subsystem, specifically in the `led_tg_check()` function. The vulnerability involves an improper LED ID check that was detected by KASAN (Kernel Address Sanitizer) and reported by Syzbot. This flaw could allow a local attacker with low privileges to achieve high impacts on confidentiality, integrity, and av [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56648

CVE-2024-56648 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's High-availability Seamless Redundancy (HSR) networking subsystem. The flaw exists in the `fill_frame_info()` function, where insufficient packet length validation could lead to out-of-bounds memory access when processing packets as small as 14 bytes. This may result in use of uninitialized values, causing undefined behavior [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56645

A reference count underflow vulnerability exists in the Linux kernel's J1939 Controller Area Network (CAN) protocol implementation. The flaw occurs in j1939_session_new() where improper socket buffer (skb) reference counting can lead to a use-after-free condition. Siemens has confirmed this vulnerability affects multiple industrial networking products running SINEC OS, including RUGGEDCOM RST2428P and SCA [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56644

A memory leak vulnerability exists in the Linux kernel's IPv6 networking subsystem. Specifically, destination (dst) objects are leaked in the `ip6_negative_advice()` function when executed for an expired IPv6 route located in the exception table. This flaw can lead to resource exhaustion over time, potentially causing denial of service conditions on affected systems. The vulnerability has been resolved in [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56643

A memory leak vulnerability in the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation affects Siemens industrial networking products. The flaw occurs in dccp_feat_change_recv where memory allocated for a new SP feature value is not freed if dccp_feat_push_confirm() fails, potentially leading to resource exhaustion. The vulnerability requires local access with low privileges and has [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56637

A race condition vulnerability exists in the Linux kernel netfilter ipset subsystem. The ip_set.ko kernel module can be unloaded by user space while simultaneously requesting a set type backend module, potentially resulting in a kernel crash. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE switch families. The issue is lo [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56636

A vulnerability in the Linux kernel's Generic Network Virtualization Encapsulation (Geneve) implementation affects Siemens industrial networking products. The flaw exists in the `geneve_xmit_skb()` function, which incorrectly assumes the MAC header is set in the output path. This assumption can lead to errors when the MAC header is not properly initialized. The vulnerability stems from using `eth_hdr()` t [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56633

A memory accounting flaw in the Linux kernel's tcp_bpf subsystem affects Siemens industrial network devices running SINEC OS. The vulnerability in __SK_REDIRECT pre-uncharges socket memory bytes (either msg->sg.size or apply_bytes), which can lead to incorrect memory accounting and potential denial of service conditions. This is a local attack vector requiring low privileges with no user interaction.

Review Siemens CVE published 2025-08-12

CVE-2024-56630

CVE-2024-56630 describes a resource leak in the OCFS2 (Oracle Cluster File System 2) Linux kernel module where iput() is not called when new_inode() succeeds but dquot_initialize() fails. This vulnerability affects Siemens industrial networking products that incorporate vulnerable Linux kernel versions, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches running SINEC OS. The flaw could lea [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-56629

CVE-2024-56629 describes a null pointer dereference vulnerability in the Linux kernel's HID Wacom driver. The issue arises when certain Wacom devices report an empty `dev->product` string, causing the driver to dereference a null pointer and potentially crash the system. While the CVE description references the Linux kernel HID subsystem, the CISA CSAF advisory ICSA-25-226-07 identifies this vulnerability [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-56619

This CVE describes a vulnerability in the nilfs2 filesystem where corrupted inode i_size values can lead to out-of-bounds memory access or use-after-free conditions when searching directory records. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting their RUGGEDCOM RST2428P and SCALANCE product families running SINEC OS, though the s [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56610

CVE-2024-56610 is a medium-severity vulnerability (CVSS 5.5) affecting the Kernel Concurrency Sanitizer (KCSAN) in Linux kernels configured with PREEMPT_RT real-time preemption. The issue stems from the `report_filterlist_lock` being implemented as a standard spinlock rather than a raw_spinlock, which can trigger invalid context warnings and potential system instability when sleeping functions are called [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56602

A use-after-free vulnerability exists in the Linux kernel's IEEE 802.15.4 (low-rate wireless personal area network) subsystem. The flaw occurs in ieee802154_create() where sock_init_data() attaches an allocated sk object to a socket, but if subsequent initialization fails, the sk object is freed while a dangling pointer remains in the socket structure. This can lead to local denial of service conditions w [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56601

A use-after-free vulnerability exists in the Linux kernel's networking stack within the `inet_create()` function. When socket initialization attaches an `sk` object to a `sock` object via `sock_init_data()`, a subsequent failure in `inet_create()` frees the `sk` object but leaves a dangling pointer in the `sock` structure. This dangling pointer can lead to memory corruption and potential privilege escalat [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56600

CVE-2024-56600 is a use-after-free vulnerability in the Linux kernel's IPv6 networking subsystem. The flaw occurs in inet6_create() where sock_init_data() attaches an allocated sk (socket) pointer to a sock object. If inet6_create() fails after this attachment, the sk object is released, but the sock object retains a dangling pointer to the freed memory. This dangling pointer can later be dereferenced, le [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56598

CVE-2024-56598 is an array-index-out-of-bounds vulnerability in the JFS (Journaled File System) implementation, specifically within the dtReadFirst function. The vulnerability occurs when the stbl value can become out of bounds due to a malformed or corrupted filesystem. A fix was implemented to add bounds checking with appropriate error code returns. The vulnerability was published on 2025-08-12 and last [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56597

CVE-2024-56597 is a vulnerability in the JFS (Journaled File System) implementation affecting Siemens industrial networking products. The flaw involves a shift-out-of-bounds condition in the dbSplit function that occurs when dmt_budmin is less than zero, potentially causing errors in subsequent operations. The fix adds an early validation check in dbAllocCtl to return an error before the problematic condi [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56596

CVE-2024-56596 describes an array-index-out-of-bounds condition in the Journaled File System (jfs) within the Linux kernel, specifically in the jfs_readdir function. The vulnerability stems from invalid values in the stbl (slot table) structure that could lead to out-of-bounds memory access. A fix was implemented to add validation checks that return an error code when invalid stbl values are detected. Thi [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-56595

CVE-2024-56595 describes an array-index-out-of-bounds vulnerability in the Journaled File System (jfs) within the Linux kernel, specifically in the dbAdjTree function. The issue occurs when a loop variable (lp) starts at 0 and becomes negative on subsequent assignment, leading to an out-of-bounds array access. This vulnerability was published on 2025-08-12 and last modified on 2026-02-25. The vulnerabilit [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-56594

CVE-2024-56594 describes a Linux kernel issue in the AMDGPU DRM driver where an incorrect max_segment_size setting could cause debug_dma_map_sg() to report over-mapping of scatter-gather (sg) lengths. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens ProductCERT issued advisory SSA-355557, which CISA republished as ICSA-25-226-07. The advisory originally listed multipl [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-56593

CVE-2024-56593 is a NULL pointer dereference vulnerability in the Linux kernel's brcmfmac Wi-Fi driver, specifically within the `brcmf_sdiod_sglist_rw()` function. The flaw manifests when a high `sd_sgentry_align` value (e.g., 512) is configured and numerous queued SKBs (socket buffers) are transmitted from the packet queue, potentially causing a kernel oops (crash). The vulnerability was published on Aug [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56587

A race condition in the Linux kernel LED class subsystem allows NULL pointer dereference via concurrent access to led_cdev attributes. The vulnerability exists when Process A adds an HID device (triggering led_cdev addition) while Process B simultaneously accesses the led_cdev attribute, resulting in a NULL pointer dereference in brightness_show(). This is a local attack vector requiring low privileges wi [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-56581

A use-after-free vulnerability exists in the btrfs filesystem's reference verification (ref-verify) component, triggered by an invalid reference action. This memory safety issue could potentially allow an attacker to corrupt memory or escalate privileges on affected systems. The vulnerability was originally published on August 12, 2025, and subsequently modified on February 25, 2026, as part of CISA's rep [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-56576

A use-after-free vulnerability exists in the Linux kernel's TC358743 HDMI-to-CSI-2 bridge driver (media: i2c: tc358743). When the driver's probe() function encounters an error after arming a polling timer, the timer is not properly cancelled before cleanup. The timer subsequently fires with pointers to already-freed memory, causing a kernel crash. This is a local attack vector requiring low privileges wit [truncated]