Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS

The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close more than two dozen bugs, including one rated 9.8 out of 10.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: an open industrial control cabinet inside a substation
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Siemens released SINEC OS version 4.0 for its RUGGEDCOM RST2428P industrial switch (part number 6GK6242-6PA00) to fix more than two dozen vulnerabilities.
  • The most serious flaw carries a CVSS score of 9.8 out of 10, meaning it can be triggered across a network without a password.
  • Affected sectors include energy, transport, critical manufacturing, healthcare, financial services and government facilities worldwide.
  • Individual bugs include CVE-2025-1352, CVE-2025-1376, CVE-2025-6052, CVE-2025-6141, CVE-2025-6170, CVE-2025-7039 and CVE-2025-8732.
  • Siemens is directing operators to update to V4.0 or later; no active exploitation has been reported.

Siemens has told industrial customers to update a widely deployed piece of network kit after disclosing a long list of security flaws in its operating system.

The device in question is the RUGGEDCOM RST2428P, an industrial ethernet switch that acts as the traffic controller for cables running between machines inside a power substation, a rail signalling cabinet, or a factory floor. It runs software called SINEC OS. Every version before 4.0 is affected. Siemens, headquartered in Germany, ships this hardware into critical manufacturing, energy, transport, healthcare, financial services and government sites globally.

The advisory was published by CISA, which routinely republishes industrial control system alerts from vendors. Three weeks earlier, we reported a similar patch from Schneider Electric for grid protection gear used in the same energy sector.

What is actually broken?

More than two dozen distinct weaknesses, most of them in open-source software libraries Siemens bundles into the product. The headline number is a CVSS score of 9.8 out of 10. CVSS is the industry's standard 0-to-10 severity scale; 9.8 means the flaw can be triggered from across the network without a password.

The named bugs cover a range of common software mistakes.

CVE-2025-1352 is a memory corruption bug in GNU elfutils, a set of tools for reading program files. It can be initiated remotely, though Siemens notes the complexity is high and reliable exploitation is difficult.

CVE-2025-6052 affects GLib, a widely used building-block library. When a program tries to add data to a very large text string, the size calculation silently wraps around and data ends up written past the end of allocated memory. That typically means a crash, sometimes worse.

CVE-2025-6141 is a stack buffer overflow in GNU ncurses, the library that handles text-based terminal displays. CVE-2025-6170 covers the same class of overflow in xmllint, a tool for checking XML files. Both require local access.

CVE-2025-7039 is a path traversal bug in glib: an integer overflow during temporary file creation lets an attacker manipulate file paths and reach data they shouldn't. CVE-2025-1376 and CVE-2025-8732 cover denial-of-service conditions in elfutils and libxml2.

The broader Siemens list also cites cross-site scripting, authentication bypass, race conditions, prototype pollution, and active debug code left in the product. That last item is exactly what it sounds like: developer test hooks that should not ship in production hardware.

Should operators be worried?

Yes, but the fix is straightforward: install SINEC OS version 4.0 or later, available from Siemens Industry Online Support.

Industrial switches are not phones. They don't update themselves, sitting instead in locked cabinets at remote sites, often behind change-control processes that take weeks. Between now and the moment those cabinets are opened, every flaw listed above is still present. That gap between patch release and patch installation is where the real risk lives.

Siemens says there are no reports of the bugs being used in real attacks, and its long-standing guidance applies: put this equipment on isolated networks, restrict who can reach it, and treat any device exposed to the wider internet as a serious risk.

For the public there's nothing to do directly. The equipment sits inside utilities and factories, not homes. But the sectors listed, power, hospitals, transit, are exactly the ones people notice when something fails.

© 2026 Threat Vectr