PatchSiren cyber security CVE debrief
CVE-2024-46665 Siemens CVE debrief
CVE-2024-46665 is a low-severity information disclosure issue affecting Siemens RUGGEDCOM APE1808. According to the supplied CISA/Siemens advisory corpus, an attacker in a man-in-the-middle position may be able to recover the RADIUS accounting server shared secret by intercepting accounting-requests. The advisory was published on 2025-02-11 and republished/updated on 2026-03-12. No CISA KEV listing is present in the supplied data.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2026-03-12
- Advisory published
- 2025-02-11
- Advisory updated
- 2026-03-12
Who should care
Siemens RUGGEDCOM APE1808 operators, OT network administrators, and security teams responsible for environments that use RADIUS accounting across potentially interceptable network paths.
Technical summary
The advisory maps CVE-2024-46665 to CWE-201 (insertion of sensitive information into sent data). The supplied CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N, reflecting a network-reachable confidentiality issue that requires a man-in-the-middle position and does not impact integrity or availability. The risk centers on exposure of the RADIUS accounting server shared secret from intercepted accounting traffic.
Defensive priority
Low overall, but worth prompt verification in OT environments that rely on RADIUS accounting and have weaker segmentation or untrusted transit paths.
Recommended defensive actions
- Confirm whether Siemens RUGGEDCOM APE1808 devices in your environment are running affected versions and using RADIUS accounting.
- Follow the Siemens/CISA advisory guidance for remediation; the supplied corpus states to update to the vendor-provided fix and contact customer support for patch and update information.
- Review network segmentation and other defense-in-depth controls around accounting and management traffic paths, using CISA industrial control system recommended practices as a baseline.
- After remediation, validate that credential- or secret-bearing traffic is not exposed to passive interception on intermediate network segments.
Evidence notes
The supplied CISA CSAF advisory (ICSA-25-044-06) identifies Siemens RUGGEDCOM APE1808 as the affected product and includes the published/modified dates used here: 2025-02-11 and 2026-03-12. The corpus also includes Siemens ProductCERT references, the CISA advisory page, the official CVE record, CWE-201, and the CVSS calculator link. One notable source inconsistency is that the vulnerability description text names FortiOS/FortiGate even though the advisory title and affected product are Siemens RUGGEDCOM APE1808; this debrief preserves that discrepancy rather than resolving it without additional evidence.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-46665 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-46665
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-46665 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-46665
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-770770.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-770770.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.