PatchSiren

siemens CVE debriefs · Page 22

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Siemens CVE published 2025-08-12

CVE-2024-46832

A vulnerability in the Linux kernel's MIPS cevt-r4k timer driver could cause a BUG warning when get_c0_compare_int is called on secondary CPUs in invalid context. The issue stems from improper handling of timer IRQ installation during CPU bring-up, potentially triggering sleeping function warnings in mutex operations. Siemens has assessed this vulnerability as 'Misinformed' impact for affected industrial [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46829

CVE-2024-46829 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's rtmutex subsystem affecting Siemens industrial networking products. The flaw occurs in rt_mutex_handle_deadlock(), which is called with rt_mutex::wait_lock held. In deadlock scenarios, the function emits a warning and enters an endless scheduling loop while still holding the lock, triggering a 'scheduling in atomic' warning [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46828

CVE-2024-46828 is a vulnerability in the Linux kernel's sch_cake network scheduler, affecting the bulk flow accounting logic used for host fairness in destination/source host fairness mode. The flaw resides in how sch_cake tracks active bulk flows per host, which serves as the round-robin weight when iterating through network flows. Incorrect accounting could lead to improper traffic scheduling, potential [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46818

CVE-2024-46818 is a vulnerability in the Linux kernel's AMD display driver (drm/amd/display) where a gpio_id value is used as an array index without proper bounds checking. The vulnerability was published on August 12, 2025, and last modified on February 25, 2026. Siemens ProductCERT issued advisory SSA-355557 addressing third-party components in SINEC OS, which was subsequently republished by CISA as ICS [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46815

CVE-2024-46815 is a vulnerability in the AMD display driver subsystem (drm/amd/display) where the code fails to validate `num_valid_sets` before accessing the `reader_wm_sets[]` array. This missing bounds check could lead to out-of-bounds memory access. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens has identified this CVE as affecting certain industrial networking [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-46814

This CVE describes a vulnerability in the Linux kernel's AMD display driver (drm/amd/display) where a msg_id check is missing before processing a transaction. The vulnerability was originally published on 2025-08-12 and last modified on 2026-02-25. The source advisory (ICSA-25-226-07) was republished by CISA based on Siemens ProductCERT advisory SSA-355557. Notably, the source advisory marks the impact as [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46800

A use-after-free vulnerability exists in the Linux kernel's netem (network emulator) scheduler. The flaw occurs in netem_dequeue() when a packet is enqueued to an inner queueing discipline (qdisc) that returns __NET_XMIT_STOLEN, potentially leading to memory corruption. This vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE swit [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46798

A use-after-free vulnerability in the Linux kernel's ALSA System on Chip (ASoC) Dynamic Audio Power Management (DAPM) subsystem. The flaw occurs when snd_pcm_suspend_all() accesses a freed snd_soc_pcm_runtime object during system suspension. This vulnerability was detected using Kernel Address Sanitizer (KASAN) configurations. The issue affects Siemens industrial networking products running SINEC OS, spec [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46791

A deadlock vulnerability exists in the Linux kernel's MCP251x CAN controller driver. The mcp251x_hw_wake() function is called with the mpc_lock mutex held and disables the interrupt handler, creating a race condition where an interrupt occurring during mcp251x_open can cause a deadlock. This affects Siemens industrial networking products running SINEC OS that incorporate the vulnerable kernel component. T [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46783

A vulnerability in the Linux kernel's tcp_bpf subsystem has been identified and resolved. The issue involves an incorrect return value in the tcp_bpf_sendmsg() function, which could lead to denial of service conditions. Siemens has confirmed this vulnerability affects multiple industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE XC/XR/XCM/XRM/XCH/XRH families. The [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46782

A use-after-free vulnerability exists in the Linux kernel's Identifier Locator Addressing (ILA) subsystem, specifically in the `ila_nf_input` function. The flaw occurs when `nf_unregister_net_hooks()` is called, leading to a use-after-free read condition. This vulnerability affects Siemens industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE switch families. The i [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46781

A use-after-free vulnerability in the nilfs2 filesystem affects Siemens industrial networking products running SINEC OS. The flaw occurs during mount-time recovery when inodes with recovered data are not properly freed if an error occurs before the log writer starts, potentially leading to memory corruption issues. CISA published this advisory on August 12, 2025, with subsequent updates through February 2 [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46780

This CVE addresses a nilfs2 filesystem vulnerability in the Linux kernel where improper mutual exclusion when accessing superblock buffers in sysfs attribute show methods could lead to pointer dereferencing and memory access issues. The vulnerability stems from missing use of nilfs->ns_sem semaphore protection during these operations. Siemens has assessed this CVE as not affecting their listed industrial [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46777

CVE-2024-46777 is a medium-severity vulnerability in the UDF (Universal Disk Format) filesystem implementation affecting Siemens industrial networking products. The flaw involves improper input validation where the UDF driver fails to adequately check partition length values during filesystem mounting operations. Specifically, the vulnerability allows mounting of filesystems with partition lengths that wo [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46771

A vulnerability in the Linux kernel's Controller Area Network (CAN) Broadcast Manager (BCM) subsystem allows a use-after-free condition when a network device is unregistered. The BCM protocol creates proc filesystem entries for CAN sockets, but these entries were not properly removed when the underlying CAN device was unregistered. This could lead to local denial of service through memory corruption or sy [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46761

A vulnerability in the PCI hotplug driver (pnv_php) for PowerNV platforms can cause a driver crash. The issue affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. A local attacker with low privileges can trigger a denial-of-service condition without user interaction. The vulnerability was disclosed on August 12, 2025, with the [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46759

CVE-2024-46759 is a medium-severity (CVSS 5.5) integer underflow vulnerability in the Linux kernel's hwmon adc128d818 driver. The flaw occurs when user-provided limit attributes are processed: DIV_ROUND_CLOSEST() is called after kstrtol() without proper bounds checking, causing an underflow when large negative numbers (e.g., -9223372036854775808) are supplied. The fix reorders clamp_val() and DIV_ROUND_CL [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46755

CVE-2024-46755 is a vulnerability in the Linux kernel's mwifiex wireless driver. The function `mwifiex_get_priv_by_id()` returns a private (`priv`) pointer based on `bss_num` and `bss_type` parameters without verifying whether that `priv` structure is currently in use. Unused `priv` pointers lack an attached `wiphy` structure, which can lead to NULL pointer dereferences in subsequent code paths that expec [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46750

A missing bridge lock in the Linux kernel's PCI subsystem could allow local attackers to cause denial-of-service conditions. The vulnerability exists in pci_bus_lock() where proper locking mechanisms were not implemented, potentially leading to race conditions. Siemens has identified affected industrial networking products running SINEC OS that incorporate the vulnerable Linux kernel component.

Review Siemens CVE published 2025-08-12

CVE-2024-46747

CVE-2024-46747 describes a slab-out-of-bounds read vulnerability in the Linux kernel's HID cougar driver. The `cougar_report_fixup` function for the Cougar 500k Gaming Keyboard failed to verify that the report descriptor size was correct before accessing it, potentially leading to memory corruption or information disclosure. This vulnerability was originally published in the Linux kernel context but appea [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46744

A vulnerability in the Linux kernel's Squashfs filesystem implementation, affecting symbolic link handling, has been resolved. The issue involved insufficient validation of symbolic link sizes, which could lead to denial of service conditions. Siemens has identified this vulnerability as affecting multiple industrial networking product families that incorporate the vulnerable Linux kernel component. The v [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46743

CVE-2024-46743 is a HIGH severity (CVSS 7.1) out-of-bounds read vulnerability in the Linux kernel's Open Firmware (OF) interrupt handling code. The flaw exists in the interrupt map walk functionality within `of/irq`, where improper bounds checking on device addresses could allow a local attacker to read memory outside intended boundaries. This vulnerability was resolved in the upstream Linux kernel with a [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46740

CVE-2024-46740 is a high-severity vulnerability in the Linux kernel binder driver, specifically a use-after-free (UAF) condition caused by offsets overwrite. The vulnerability was published on August 12, 2025, and most recently modified on February 25, 2026. Siemens has identified this vulnerability as affecting multiple industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46739

A NULL pointer dereference vulnerability exists in the Linux kernel's uio_hv_generic driver, specifically in the hv_uio_rescind function. This flaw can lead to a kernel crash (denial of service) when triggered. The vulnerability affects Siemens industrial networking products running SINEC OS, including RUGGEDCOM RST2428P switches and multiple SCALANCE switch families. The issue is rated MEDIUM severity wi [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46738

A use-after-free vulnerability exists in the VMCI (Virtual Machine Communication Interface) subsystem, specifically within the vmci_resource_remove() function. This flaw can be triggered when removing a resource, potentially allowing a local attacker with low privileges to execute arbitrary code, escalate privileges, or cause a denial of service. The vulnerability affects Siemens industrial networking pro [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-46737

A vulnerability in the Linux kernel's NVMe-oF TCP target (nvmet-tcp) implementation can cause a kernel crash when command allocation fails. The flaw exists in the NVMe over Fabrics TCP transport layer, where improper handling of memory allocation failures leads to a NULL pointer dereference or similar crash condition. This affects Siemens industrial networking products that incorporate the vulnerable kern [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-46731

CVE-2024-46731 describes an out-of-bounds read vulnerability in the Linux kernel's drm/amd/pm (AMD Power Management) subsystem. The flaw occurs when an index calculation (i - 1U) can underflow when i equals zero, causing an access beyond the bounds of the mc_data[] array. This vulnerability was originally published in the Linux kernel context but appears in Siemens industrial control system advisories due [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-46725

CVE-2024-46725 describes an out-of-bounds write vulnerability in the Linux kernel's drm/amdgpu driver, caused by an unchecked ring type value. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. CISA's advisory ICSA-25-226-07, which was republished on 2026-02-25 based on Siemens ProductCERT advisory SSA-355557, identifies this CVE as affecting Siemens industrial networking produ [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-46724

CVE-2024-46724 is an out-of-bounds read vulnerability in the Linux kernel's drm/amdgpu driver, specifically affecting the df_v1_7_channel_number field. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. According to CISA's ICS advisory ICSA-25-226-07, this vulnerability was initially listed as affecting Siemens industrial networking products including the RUGGEDCOM RST2428P and [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-46723

CVE-2024-46723 describes an out-of-bounds read vulnerability in the Linux kernel's drm/amdgpu driver when accessing the ucode[] array. The vulnerability was published on 2025-08-12 and last modified on 2026-02-25. Siemens ProductCERT issued advisory SSA-355557 addressing this issue, which CISA subsequently republished as ICSA-25-226-07 on 2025-08-12 with updates through 2026-02-25. The advisory covers Sie [truncated]