Siemens SINEC OS

Plan PatchCVSS 9.8ICS-CERT ICSA-26-188-05Jun 2, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

SINEC OS before V4.0 in RUGGEDCOM RST2428P contains multiple vulnerabilities including memory corruption (CWE-119, CWE-121, CWE-787), resource exhaustion (CWE-835), improper input validation (CWE-20), path traversal (CWE-22), and access control weaknesses (CWE-284). These flaws allow remote code execution without authentication or user interaction. Siemens has released version 4.0 with fixes for these issues.

What this means
What could happen
An attacker with network access to RUGGEDCOM RST2428P could exploit multiple vulnerabilities to execute code remotely, potentially disrupting network connectivity, gaining unauthorized access to industrial control systems, or causing equipment to malfunction.
Who's at risk
Water and electric utilities operating RUGGEDCOM RST2428P industrial Ethernet switches in critical control networks. This switch manages connectivity between RTUs, PLCs, and SCADA servers, making it a key choke point for industrial network traffic.
How it could be exploited
An attacker on the network could send specially crafted packets to the RUGGEDCOM RST2428P device to trigger memory corruption, input validation, or other weaknesses in SINEC OS. Successful exploitation would allow arbitrary code execution on the device, giving the attacker control over the industrial Ethernet switch and access to connected control systems.
Prerequisites
  • Network access to RUGGEDCOM RST2428P device on industrial network
  • Device running SINEC OS version before V4.0
  • No authentication required for exploitation
remotely exploitableno authentication requiredlow complexitycritical severitymultiple vulnerability typesaffects network infrastructure
Exploitability
Some exploitation risk — EPSS score 2.2%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
RUGGEDCOM RST2428P (6GK6242-6PA00)< 4.04.0
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate RUGGEDCOM RST2428P to SINEC OS version 4.0 or later
CVEs (77)
API: /api/v1/advisories/6496d720-8492-4526-a509-b04aafff7e8b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens SINEC OS | CVSS 9.8 - OTPulse