PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-24924 GMOD CVE debrief

CVE-2025-24924 affects GMOD Apollo versions before 2.8.0. According to the CISA advisory, certain functionality can be reached without authentication when passed an administrative username. GMOD’s remediation is to update to version 2.8.0. Because Apollo is covered in a CISA industrial control systems advisory, defenders should treat this as a priority authentication issue and verify exposure in any deployed environments.

Vendor
GMOD
Product
Apollo
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-04
Original CVE updated
2025-03-04
Advisory published
2025-03-04
Advisory updated
2025-03-04

Who should care

Organizations using GMOD Apollo, especially industrial control system operators, administrators, and security teams responsible for network-facing Apollo deployments or administrative access paths.

Technical summary

CISA’s CSAF advisory identifies GMOD Apollo < 2.8.0 as affected by an authentication-related weakness: certain functionality does not require authentication when an administrative username is supplied. The advisory lists the fix as Apollo 2.8.0. The included CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N, indicating network reachability, low attack complexity, and high integrity impact.

Defensive priority

High for exposed Apollo deployments. The issue is publicly documented by CISA and has a vendor-recommended fix available, so remediation should be scheduled promptly and validated in affected environments.

Recommended defensive actions

  • Upgrade GMOD Apollo to version 2.8.0 or later as recommended by GMOD.
  • Inventory all Apollo deployments and confirm which instances are below 2.8.0.
  • Review administrative account usage and restrict administrative usernames and access paths to trusted operators only.
  • Monitor authentication-related logs and administrative activity for unexpected access attempts or privilege-use anomalies.
  • Follow CISA industrial control system defensive guidance and apply layered access controls around Apollo deployments.

Evidence notes

All claims are drawn from the supplied CISA CSAF source item and its listed references. The source states that GMOD Apollo < 2.8.0 is affected, that certain functionality does not require authentication when passed with an administrative username, and that the remediation is to update to version 2.8.0. Timing in this debrief uses the CVE/source publication date of 2025-03-04.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-24924 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-24924

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-24924 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24924

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.