ICSA-25-162-04: Siemens SCALANCE and RUGGEDCOM
CISA advisory · released 2025-06-10
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 3, 2026-01-14 (final)
CISA's summary
Summary: Several Industrial Communication Devices based on SINEC OS before V3.2 contain multiple vulnerabilities that could allow an attacker to circumvent authorization checks and perform actions that exceed the permissions of the "guest" role. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | RUGGEDCOM RST2428P (6GK6242-6PA00) | vers:intdot/<3.2 |
| Siemens | SCALANCE XC316-8 (6GK5324-8TS00-2AC2) | vers:all/* |
| Siemens | SCALANCE XC324-4 (6GK5328-4TS00-2AC2) | vers:all/* |
| Siemens | SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) | vers:all/* |
| Siemens | SCALANCE XC332 (6GK5332-0GA00-2AC2) | vers:all/* |
| Siemens | SCALANCE XC416-8 (6GK5424-8TR00-2AC2) | vers:all/* |
| Siemens | SCALANCE XC424-4 (6GK5428-4TR00-2AC2) | vers:all/* |
| Siemens | SCALANCE XC432 (6GK5432-0GR00-2AC2) | vers:all/* |
| Siemens | SCALANCE XCH328 (6GK5328-4TS01-2EC2) | vers:intdot/<3.2 |
| Siemens | SCALANCE XCM324 (6GK5324-8TS01-2AC2) | vers:intdot/<3.2 |
| Siemens | SCALANCE XCM328 (6GK5328-4TS01-2AC2) | vers:intdot/<3.2 |
| Siemens | SCALANCE XCM332 (6GK5332-0GA01-2AC2) | vers:intdot/<3.2 |
| Siemens | SCALANCE XR302-32 (6GK5334-5TS00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR302-32 (6GK5334-5TS00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR302-32 (6GK5334-5TS00-4AR3) | vers:all/* |
| Siemens | SCALANCE XR322-12 (6GK5334-3TS00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR322-12 (6GK5334-3TS00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR322-12 (6GK5334-3TS00-4AR3) | vers:all/* |
| Siemens | SCALANCE XR326-8 (6GK5334-2TS00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR326-8 (6GK5334-2TS00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR326-8 (6GK5334-2TS00-4AR3) | vers:all/* |
| Siemens | SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3) | vers:all/* |
| Siemens | SCALANCE XR502-32 (6GK5534-5TR00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR502-32 (6GK5534-5TR00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR502-32 (6GK5534-5TR00-4AR3) | vers:all/* |
| Siemens | SCALANCE XR522-12 (6GK5534-3TR00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR522-12 (6GK5534-3TR00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR522-12 (6GK5534-3TR00-4AR3) | vers:all/* |
| Siemens | SCALANCE XR526-8 (6GK5534-2TR00-2AR3) | vers:all/* |
| Siemens | SCALANCE XR526-8 (6GK5534-2TR00-3AR3) | vers:all/* |
| Siemens | SCALANCE XR526-8 (6GK5534-2TR00-4AR3) | vers:all/* |
| Siemens | SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) | vers:intdot/<3.2 |
| Siemens | SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) | vers:intdot/<3.2 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2025-40567 — CVE-2025-40567 · CWE-863
The "Load Rollback" functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to make the affected product roll back configuration changes made by privileged users.
- CVE-2025-40568 — CVE-2025-40568 · CWE-863
An internal session termination functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to terminate legitimate users' sessions.
- CVE-2025-40569 — CVE-2025-40569 · CWE-362
The "Load Configuration from Local PC" functionality in the web interface of affected products contains a race condition vulnerability. This could allow an authenticated remote attacker to make the affected product load an attacker controlled configuration instead of the legitimate one. Successful exploitation requires that a legitimate administrator invokes the functionality and the attacker wins the race condition.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reported these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.