PatchSiren cyber security CVE debrief
CVE-2024-43485 Siemens CVE debrief
CVE-2024-43485 is a high-severity denial-of-service vulnerability associated with Siemens INTRALOG WMS in the supplied CISA/Siemens advisory material. The advisory indicates a network-reachable issue with no privileges and no user interaction required, and Siemens recommends updating to V5 or later.
- Vendor
- Siemens
- Product
- INTRALOG WMS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-13
- Original CVE updated
- 2025-05-13
- Advisory published
- 2025-05-13
- Advisory updated
- 2025-05-13
Who should care
Siemens INTRALOG WMS operators, OT/ICS administrators, and security teams responsible for patching and availability management in environments where the product is deployed.
Technical summary
The supplied advisory metadata classifies the issue with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a remotely reachable, unauthenticated availability impact with no confidentiality or integrity impact. The source description labels the issue as a ".NET and Visual Studio Denial of Service Vulnerability," while the affected product mapping points to Siemens INTRALOG WMS. The remediation provided in the source corpus is to update to V5 or later.
Defensive priority
High. Prioritize affected deployments, especially where a service interruption would affect operational continuity.
Recommended defensive actions
- Update Siemens INTRALOG WMS to V5 or later, per the vendor remediation guidance.
- Inventory all deployments of Siemens INTRALOG WMS and confirm which versions are exposed or in active use.
- Restrict network access to the affected system and segment it from less-trusted networks where possible.
- Apply standard ICS defense-in-depth and recommended-practices guidance from CISA and Siemens.
- Validate operational backups and recovery procedures so availability recovery is faster if service disruption occurs.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-25-135-02, published 2025-05-13, and the referenced Siemens advisory SSA-901508. The source metadata lists Siemens as the vendor, INTRALOG WMS as the affected product, and the remediation as updating to V5 or later. The CVSS vector in the source corpus is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-43485 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-43485
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-43485 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-43485
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-135-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-901508.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-901508.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.