Siemens SINEC OS
Plan PatchCVSS 9.8ICS-CERT ICSA-26-188-05Jun 2, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
SINEC OS before V4.0 in RUGGEDCOM RST2428P contains multiple vulnerabilities including memory corruption (CWE-119, CWE-121, CWE-787), resource exhaustion (CWE-835), improper input validation (CWE-20), path traversal (CWE-22), and access control weaknesses (CWE-284). These flaws allow remote code execution without authentication or user interaction. Siemens has released version 4.0 with fixes for these issues.
What this means
What could happen
An attacker with network access to RUGGEDCOM RST2428P could exploit multiple vulnerabilities to execute code remotely, potentially disrupting network connectivity, gaining unauthorized access to industrial control systems, or causing equipment to malfunction.
Who's at risk
Water and electric utilities operating RUGGEDCOM RST2428P industrial Ethernet switches in critical control networks. This switch manages connectivity between RTUs, PLCs, and SCADA servers, making it a key choke point for industrial network traffic.
How it could be exploited
An attacker on the network could send specially crafted packets to the RUGGEDCOM RST2428P device to trigger memory corruption, input validation, or other weaknesses in SINEC OS. Successful exploitation would allow arbitrary code execution on the device, giving the attacker control over the industrial Ethernet switch and access to connected control systems.
Prerequisites
- Network access to RUGGEDCOM RST2428P device on industrial network
- Device running SINEC OS version before V4.0
- No authentication required for exploitation
remotely exploitableno authentication requiredlow complexitycritical severitymultiple vulnerability typesaffects network infrastructure
Exploitability
Some exploitation risk — EPSS score 2.2%
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate RUGGEDCOM RST2428P to SINEC OS version 4.0 or later
CVEs (77)
CVE-2025-1352CVE-2025-1376CVE-2025-6052CVE-2025-6141CVE-2025-6170CVE-2025-7039CVE-2025-8732CVE-2025-9086CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-10966CVE-2025-13465CVE-2025-13601CVE-2025-39913CVE-2025-40214CVE-2025-40248CVE-2025-40250CVE-2025-40251CVE-2025-40252CVE-2025-40254CVE-2025-40257CVE-2025-40258CVE-2025-40261CVE-2025-40262CVE-2025-40263CVE-2025-40264CVE-2025-40271CVE-2025-40278CVE-2025-40280CVE-2025-40281CVE-2025-40345CVE-2025-46394CVE-2025-49794CVE-2025-49795CVE-2025-49796CVE-2025-60876CVE-2025-66382CVE-2025-66412CVE-2025-69720CVE-2025-71185CVE-2025-71186CVE-2025-71188CVE-2025-71189CVE-2025-71190CVE-2025-71191CVE-2026-1484CVE-2026-1489CVE-2026-3784CVE-2026-22610CVE-2026-22976CVE-2026-22977CVE-2026-23025CVE-2026-23026CVE-2026-23030CVE-2026-23031CVE-2026-23032CVE-2026-23033CVE-2026-23037CVE-2026-23038CVE-2026-23111CVE-2026-23112CVE-2026-23220CVE-2026-23222CVE-2026-23228CVE-2026-23229CVE-2026-23230CVE-2026-23231CVE-2026-23236CVE-2026-23238CVE-2026-24515CVE-2026-25210CVE-2026-26157CVE-2026-26158CVE-2026-35535CVE-2026-41918CVE-2025-66035
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/6496d720-8492-4526-a509-b04aafff7e8bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.