PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35279 Siemens CVE debrief

CVE-2024-35279 is a high-severity network-facing vulnerability reported in the supplied advisory corpus and first published by CISA on 2025-02-11. The source data maps the CVE to Siemens RUGGEDCOM APE1808, and later notes a 2026-03-12 CISA republication update based on Siemens ProductCERT SSA-770770. The advisory text in the corpus also contains an upstream Fortinet FortiOS CAPWAP/UDP buffer-overflow description, so the safest reading is to follow the linked Siemens/CISA remediation guidance and treat exposed fabric-service or CAPWAP access as sensitive.

Vendor
Siemens
Product
RUGGEDCOM APE1808
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-11
Original CVE updated
2026-03-12
Advisory published
2025-02-11
Advisory updated
2026-03-12

Who should care

OT/ICS defenders, Siemens RUGGEDCOM APE1808 operators, industrial network administrators, and incident responders responsible for exposed edge or management interfaces.

Technical summary

The supplied description characterizes CVE-2024-35279 as a stack-based buffer overflow reachable by crafted UDP packets through CAPWAP control. The advisory says a remote unauthenticated attacker could potentially execute arbitrary code or commands if FortiOS stack protections are bypassed and the fabric service is exposed on the interface. In the same source corpus, the affected-product metadata points to Siemens RUGGEDCOM APE1808, while the remediation text recommends removing the fabric service or blocking CAPWAP-CONTROL access to UDP port 5246 and references an update to Fortigate NGFW V7.4.7.

Defensive priority

Immediate for any exposed deployment; otherwise high priority for validation, access restriction, and patch planning.

Recommended defensive actions

  • Review whether any affected interface exposes fabric service or CAPWAP control traffic.
  • Block or strictly limit CAPWAP-CONTROL access to UDP port 5246 using local-in policy where applicable.
  • Remove the fabric service from interfaces that do not require it.
  • Follow the linked Siemens ProductCERT SSA-770770 and CISA ICSA-25-044-06 guidance for vendor remediation details.
  • Plan and apply the vendor-recommended update path referenced in the advisory corpus.
  • Inventory Siemens RUGGEDCOM APE1808 deployments and confirm whether any are internet-facing or reachable from untrusted networks.
  • Monitor for unusual UDP traffic to CAPWAP-related ports on exposed industrial interfaces.

Evidence notes

The source corpus is internally inconsistent: the CSAF metadata identifies Siemens RUGGEDCOM APE1808 as the affected product, but the advisory description text repeated in the same record refers to a Fortinet FortiOS CAPWAP issue. This debrief preserves both source facts without reconciling them beyond the evidence provided. Timing references are taken from the supplied CVE and advisory timeline: published 2025-02-11 and republished/updated 2026-03-12.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35279 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35279

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35279 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35279

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-770770.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-770770.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.