PatchSiren cyber security CVE debrief
CVE-2024-52965 Siemens CVE debrief
CVE-2024-52965 is a high-severity authentication issue described as a missing critical step in authentication (CWE-304) that can allow API login even when a certificate is invalid. The supplied source corpus is inconsistent, however: the CVE description names Fortinet FortiOS/FortiProxy versions, while the CSAF advisory and product tree identify Siemens RUGGEDCOM APE1808. Treat the advisory as requiring manual verification before remediation is assigned to any environment.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2026-03-12
- Advisory published
- 2025-02-11
- Advisory updated
- 2026-03-12
Who should care
Asset owners, OT/industrial security teams, and vulnerability managers responsible for systems referenced in Siemens ProductCERT advisory SSA-770770 / CISA ICSA-25-044-06 should review this immediately. Teams that rely on API-key plus certificate-based authentication should also verify whether any exposed assets match the CVE description or the Siemens product tree, because the source data is conflicting.
Technical summary
The CVE record describes a missing authentication step that may let an API user authenticate using api-key plus PKI user certificate authentication even when the certificate is invalid. The CVSS vector supplied in the source indicates network reachability with high privileges required (CVSS 3.1 vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), yielding a 7.2 HIGH score. The source corpus also contains a product/vendor mismatch: the vulnerability text refers to Fortinet products, while the CSAF advisory maps the issue to Siemens RUGGEDCOM APE1808.
Defensive priority
High for environments using certificate-based API authentication, but remediation should be gated by source verification because the affected product mapping is inconsistent. Confirm the exact asset population first, then apply vendor guidance and update controls for certificate validation and API access.
Recommended defensive actions
- Cross-check affected assets against both the CVE text and the Siemens CSAF product tree before scheduling remediation.
- Use the official Siemens ProductCERT advisory SSA-770770 and CISA ICSA-25-044-06 to confirm the correct fix and affected versions.
- Validate whether any API users rely on api-key plus certificate authentication and review certificate validation logic and access control.
- Apply vendor-recommended updates or mitigations only after confirming the correct product mapping; do not rely on the conflicting remediation text without verification.
- Review authentication logs for unexpected API login activity and investigate any successful logins that used invalid or expired certificates.
- Update vulnerability-management records to reflect the source-data conflict so follow-up remediation targets the correct platform.
Evidence notes
Published date used for timing context: 2025-02-11. The source item was later republished/updated on 2026-03-12, with a note that the update was based on Siemens ProductCERT advisory SSA-770770. The corpus conflicts in multiple places: the CVE description names Fortinet FortiOS/FortiProxy versions, the CSAF advisory and affected product tree list Siemens RUGGEDCOM APE1808, and the remediation field references Fortigate NGFW V7.4.7. Because of these inconsistencies, the safest interpretation is that the record must be verified directly against the official vendor references before operational use.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-52965 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-52965
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-52965 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-52965
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-770770.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-770770.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.