PatchSiren

siemens CVE debriefs · Page 30

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35976

CVE-2024-35976 is a medium-severity vulnerability (CVSS 6.7) affecting the Linux kernel's XDP socket (xsk) subsystem, specifically involving improper validation of user input for XDP_UMEM_COMPLETION_FILL_RING operations. The vulnerability was published on April 9, 2024, and last modified on May 14, 2026. Siemens has identified this vulnerability as affecting the GNU/Linux subsystem within its SIMATIC S7-1 [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35973

CVE-2024-35973 is a medium-severity vulnerability (CVSS 5.5) affecting the GENEVE tunneling implementation in the Linux kernel, specifically in the `geneve_xmit_skb` function. The issue involves improper header validation that could lead to a denial-of-service condition. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35969

A race condition vulnerability exists in the Linux kernel IPv6 networking subsystem between ipv6_get_ifaddr and ipv6_del_addr. The flaw could allow a local attacker to cause a denial of service condition. The vulnerability affects Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X family switches. Siemens has released updates to address this issue.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35962

CVE-2024-35962 is a medium-severity vulnerability (CVSS 5.5) in the Linux kernel's netfilter subsystem, affecting Siemens industrial network devices running SINEC OS. The issue involves incomplete validation of user input in netfilter, which could allow a local attacker with low privileges to cause a denial of service condition. The vulnerability was published on August 12, 2025, with subsequent modificat [truncated]

CRITICAL Siemens CVE published 2025-08-12

CVE-2024-35960

A critical vulnerability in the Mellanox mlx5 driver affects Siemens industrial network devices. The flaw involves improper linking of flow steering (fs) rules into the rule tree, which can lead to integrity and availability impacts on affected systems. The vulnerability is network-accessible without authentication, making it particularly severe for exposed industrial control systems.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35958

CVE-2024-35958 is a vulnerability in the Amazon Elastic Network Adapter (ENA) driver for Linux, specifically affecting the net: ena subsystem. The issue involves incorrect descriptor free behavior that can lead to memory corruption or system instability. The vulnerability has been assigned a CVSS 3.1 score of 5.5 (MEDIUM severity) with the vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local att [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-35955

A use-after-free vulnerability in the Linux kernel's kprobes subsystem affects Siemens industrial networking products running SINEC OS. The flaw occurs during kprobe registration and could allow an attacker with local privileges to achieve code execution. Siemens has released updates to address this issue in affected SCALANCE and RUGGEDCOM devices.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-35947

CVE-2024-35947 is a medium-severity vulnerability in the Linux kernel's dynamic debug (dyndbg) subsystem, specifically within the >control parser. The issue stems from a BUG_ON assertion dating to 2009 that could trigger under certain parsing conditions, potentially causing a kernel panic and resulting in denial of service. The vulnerability was resolved by replacing the BUG_ON with proper error handling [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-35855

A use-after-free vulnerability exists in the Linux kernel's Mellanox Spectrum switch driver (mlxsw) ACL TCAM subsystem. The flaw occurs when the rule activity update delayed work traverses configured rules while the rehash delayed work concurrently modifies the same entry pointer, leading to a race condition. The vulnerability was resolved by performing the activity query under the vregion->lock mutex to [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-35854

A use-after-free vulnerability in the Linux kernel's Mellanox Spectrum switch driver (mlxsw) could allow local attackers to cause memory corruption. The flaw occurs in the ACL TCAM rehash mechanism where a region containing active filters may be prematurely destroyed following a failed migration, leading to slab-use-after-free conditions when subsequent operations reference the freed memory. The vulnerabi [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-35852

A memory leak vulnerability exists in the Linux kernel's Mellanox Spectrum switch driver (mlxsw) within the ACL TCAM rehash work handling. The issue occurs when ACL region dismantle cancels a pending rehash work that has associated allocation hints, causing those hints to leak. The root cause stems from a logic change where non-negative credit counts no longer reliably indicate migration completion, allow [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-35848

A race condition in the Linux kernel's at24 EEPROM driver could lead to memory corruption. The vulnerability occurs when an EEPROM device is not accessible: the driver registers an nvmem device, the read operation fails, and the device is torn down. If another driver accesses the nvmem device after teardown, it references invalid memory. The fix moves the failure point to occur before nvmem device registr [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-35835

This CVE addresses a double-free vulnerability in the Linux kernel's Mellanox mlx5e driver, specifically within the `arfs_create_groups` function. A double-free occurs when memory is freed twice, potentially leading to memory corruption, system instability, or code execution. The vulnerability was resolved in the Linux kernel, and Siemens has assessed this as affecting certain industrial networking produc [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-35833

A memory leak vulnerability in the Freescale (NXP) QDMA engine driver (fsl-qdma) within the Linux kernel. The flaw occurs in queue command DMA handling where allocated memory is not properly freed, leading to resource exhaustion over time. This affects Siemens industrial networking products running SINEC OS, which incorporates the vulnerable Linux kernel component. The vulnerability was resolved in the up [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-35247

CVE-2024-35247 is a Linux kernel vulnerability in the FPGA region subsystem that could lead to a null pointer dereference during FPGA programming operations. The issue stems from the fpga region implementation assuming that low-level modules register a driver for the parent device and use its owner pointer for module reference counting. When the parent device lacks a driver, this assumption fails, potenti [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-31076

## Summary CVE-2024-31076 is a Linux kernel vulnerability in the x86 interrupt vector management subsystem that can cause a CPU vector resource leak during CPU hotplug operations. The issue occurs when interrupt affinity is reconfigured via procfs and the original CPU goes offline before the interrupt triggers on the new target CPU, preventing proper cleanup of the old vector allocation. ## Technical Anal [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-27417

A vulnerability in the Linux kernel's IPv6 networking subsystem could allow a reference leak of 'struct net' in the inet6_rtm_getaddr() function. This flaw, resolved in the upstream kernel, affects Siemens industrial networking products running SINEC OS. The vulnerability stems from improper reference counting that could lead to resource exhaustion over time. Siemens has assessed the impact as 'Misinforme [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-27416

A vulnerability in the Linux kernel's Bluetooth subsystem, specifically in the handling of HCI_EV_IO_CAPA_REQUEST events in hci_event.c, has been resolved. The issue was addressed in the Bluetooth stack to properly handle IO capability request events. Siemens has identified this vulnerability as affecting certain industrial networking products that utilize the affected Linux kernel Bluetooth components, i [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-27414

CVE-2024-27414 is a vulnerability in the Linux kernel's rtnetlink subsystem related to improper error handling logic when writing back IFLA_BRIDGE_FLAGS. The vulnerability was resolved in the Linux kernel with a fix to the error logic for IFLA_BRIDGE_FLAGS writing back. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM R [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-27413

A vulnerability in the Linux kernel's EFI capsule-loader subsystem, where an incorrect allocation size could lead to memory safety issues. The flaw was resolved by correcting the allocation size calculation in the capsule-loader code. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switch [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-27412

A vulnerability in the Linux kernel's power supply driver (bq27xxx-i2c) could lead to improper interrupt handling. The issue involves freeing a non-existent IRQ (interrupt request), which may cause system instability or undefined behavior. Siemens has identified this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family s [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-27410

CVE-2024-27410 is a vulnerability in the Linux kernel's WiFi subsystem (nl80211) that was resolved by rejecting interface type changes when accompanied by mesh ID changes. The vulnerability stems from improper handling of simultaneous interface type and mesh ID modifications in the netlink 802.11 configuration interface. Siemens has identified this CVE as affecting its industrial networking products, spec [truncated]

Review Siemens CVE published 2025-08-12

CVE-2024-27405

CVE-2024-27405 is a vulnerability in the Linux kernel's USB gadget NCM (Network Control Model) subsystem. The issue involves improper handling of datagrams within properly parsed NTBs (NCM Transfer Blocks), which could result in data loss or communication failures in USB networking implementations. The vulnerability was resolved by ensuring datagrams are not dropped when NTBs are correctly parsed. Siemens [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-27396

A use-after-free vulnerability exists in the Linux kernel's GTP (GPRS Tunneling Protocol) network subsystem. The flaw occurs in the gtp_dellink function where call_rcu is invoked during an hlist_for_each_entry_rcu traversal outside of an RCU read critical section. This timing window allows the RCU grace period to complete during iteration, potentially freeing memory while still being accessed. The vulnera [truncated]

HIGH Siemens CVE published 2025-08-12

CVE-2024-27395

A Use-After-Free vulnerability exists in the Linux kernel's Open vSwitch (ovs) connection tracking (ct) exit path. The flaw occurs in `ovs_ct_limit_exit` where `hlist_for_each_entry_rcu` is used to traverse a hash list, but `kfree_rcu` is called outside the RCU read critical section. This timing gap allows the RCU grace period to pass during traversal, potentially freeing the key before the loop completes [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-27020

A data-race vulnerability in the Linux kernel's netfilter nf_tables subsystem, specifically in nft_expr_type_get(), affects Siemens SIMATIC S7-1500 TM MFP industrial control systems running the GNU/Linux subsystem. The vulnerability was resolved in the upstream Linux kernel. Siemens has not released a patch for the affected product; mitigation relies on access controls and trusted application practices.

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-27013

A vulnerability in the Linux kernel's TUN/TAP driver could allow an attacker to cause a denial of service (DoS) condition through soft lockup. The issue occurs when the `vhost_worker` calls TUN callbacks to receive packets. If a high volume of illegal packets arrives, the `tun_do_read` function continuously dumps packet contents to the console. When console output is enabled, this excessive logging consum [truncated]

MEDIUM Siemens CVE published 2025-08-12

CVE-2024-27004

A vulnerability in the Linux kernel clock framework could allow a local attacker to cause a denial-of-service condition. The issue occurs when the kernel's clock subsystem walks the clock tree during the disable_unused operation without first obtaining a runtime PM (Power Management) reference. This race condition can lead to use-after-free or null pointer dereference scenarios when clock providers are po [truncated]

NONE Siemens CVE published 2025-08-12

CVE-2024-27000

A missing spinlock in the Freescale i.MX28 AUART driver (mxs-auart) can trigger a kernel warning when Bluetooth drivers invoke uart_handle_cts_change() without holding the required uport->lock. The upstream Linux kernel fix adds proper locking around CTS state changes. Siemens has confirmed this affects select SCALANCE and RUGGEDCOM industrial switches running SINEC OS, with updates available in V3.1 or later.

NONE Siemens CVE published 2025-08-12

CVE-2024-26997

A variable dereference issue in the DesignWare USB 2.0 (DWC2) host controller driver's Descriptor DMA (DDMA) completion flow was resolved in the Linux kernel. The vulnerability affected Siemens industrial networking products running SINEC OS, specifically the RUGGEDCOM RST2428P and SCALANCE X-family switches. Siemens has addressed this through updates to SINEC OS V3.1 or later. The CVSS vector indicates n [truncated]