PatchSiren cyber security CVE debrief
CVE-2024-35279 Siemens CVE debrief
CVE-2024-35279 is a high-severity network-facing vulnerability reported in the supplied advisory corpus and first published by CISA on 2025-02-11. The source data maps the CVE to Siemens RUGGEDCOM APE1808, and later notes a 2026-03-12 CISA republication update based on Siemens ProductCERT SSA-770770. The advisory text in the corpus also contains an upstream Fortinet FortiOS CAPWAP/UDP buffer-overflow description, so the safest reading is to follow the linked Siemens/CISA remediation guidance and treat exposed fabric-service or CAPWAP access as sensitive.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2026-03-12
- Advisory published
- 2025-02-11
- Advisory updated
- 2026-03-12
Who should care
OT/ICS defenders, Siemens RUGGEDCOM APE1808 operators, industrial network administrators, and incident responders responsible for exposed edge or management interfaces.
Technical summary
The supplied description characterizes CVE-2024-35279 as a stack-based buffer overflow reachable by crafted UDP packets through CAPWAP control. The advisory says a remote unauthenticated attacker could potentially execute arbitrary code or commands if FortiOS stack protections are bypassed and the fabric service is exposed on the interface. In the same source corpus, the affected-product metadata points to Siemens RUGGEDCOM APE1808, while the remediation text recommends removing the fabric service or blocking CAPWAP-CONTROL access to UDP port 5246 and references an update to Fortigate NGFW V7.4.7.
Defensive priority
Immediate for any exposed deployment; otherwise high priority for validation, access restriction, and patch planning.
Recommended defensive actions
- Review whether any affected interface exposes fabric service or CAPWAP control traffic.
- Block or strictly limit CAPWAP-CONTROL access to UDP port 5246 using local-in policy where applicable.
- Remove the fabric service from interfaces that do not require it.
- Follow the linked Siemens ProductCERT SSA-770770 and CISA ICSA-25-044-06 guidance for vendor remediation details.
- Plan and apply the vendor-recommended update path referenced in the advisory corpus.
- Inventory Siemens RUGGEDCOM APE1808 deployments and confirm whether any are internet-facing or reachable from untrusted networks.
- Monitor for unusual UDP traffic to CAPWAP-related ports on exposed industrial interfaces.
Evidence notes
The source corpus is internally inconsistent: the CSAF metadata identifies Siemens RUGGEDCOM APE1808 as the affected product, but the advisory description text repeated in the same record refers to a Fortinet FortiOS CAPWAP issue. This debrief preserves both source facts without reconciling them beyond the evidence provided. Timing references are taken from the supplied CVE and advisory timeline: published 2025-02-11 and republished/updated 2026-03-12.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-35279 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-35279
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-35279 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35279
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-770770.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-770770.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.