PatchSiren cyber security CVE debrief
CVE-2025-24924 GMOD CVE debrief
CVE-2025-24924 affects GMOD Apollo versions before 2.8.0. According to the CISA advisory, certain functionality can be reached without authentication when passed an administrative username. GMOD’s remediation is to update to version 2.8.0. Because Apollo is covered in a CISA industrial control systems advisory, defenders should treat this as a priority authentication issue and verify exposure in any deployed environments.
- Vendor
- GMOD
- Product
- Apollo
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-04
- Original CVE updated
- 2025-03-04
- Advisory published
- 2025-03-04
- Advisory updated
- 2025-03-04
Who should care
Organizations using GMOD Apollo, especially industrial control system operators, administrators, and security teams responsible for network-facing Apollo deployments or administrative access paths.
Technical summary
CISA’s CSAF advisory identifies GMOD Apollo < 2.8.0 as affected by an authentication-related weakness: certain functionality does not require authentication when an administrative username is supplied. The advisory lists the fix as Apollo 2.8.0. The included CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N, indicating network reachability, low attack complexity, and high integrity impact.
Defensive priority
High for exposed Apollo deployments. The issue is publicly documented by CISA and has a vendor-recommended fix available, so remediation should be scheduled promptly and validated in affected environments.
Recommended defensive actions
- Upgrade GMOD Apollo to version 2.8.0 or later as recommended by GMOD.
- Inventory all Apollo deployments and confirm which instances are below 2.8.0.
- Review administrative account usage and restrict administrative usernames and access paths to trusted operators only.
- Monitor authentication-related logs and administrative activity for unexpected access attempts or privilege-use anomalies.
- Follow CISA industrial control system defensive guidance and apply layered access controls around Apollo deployments.
Evidence notes
All claims are drawn from the supplied CISA CSAF source item and its listed references. The source states that GMOD Apollo < 2.8.0 is affected, that certain functionality does not require authentication when passed with an administrative username, and that the remediation is to update to version 2.8.0. Timing in this debrief uses the CVE/source publication date of 2025-03-04.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24924 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24924
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24924 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24924
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.