PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-52965 Siemens CVE debrief

CVE-2024-52965 is a high-severity authentication issue described as a missing critical step in authentication (CWE-304) that can allow API login even when a certificate is invalid. The supplied source corpus is inconsistent, however: the CVE description names Fortinet FortiOS/FortiProxy versions, while the CSAF advisory and product tree identify Siemens RUGGEDCOM APE1808. Treat the advisory as requiring manual verification before remediation is assigned to any environment.

Vendor
Siemens
Product
RUGGEDCOM APE1808
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-11
Original CVE updated
2026-03-12
Advisory published
2025-02-11
Advisory updated
2026-03-12

Who should care

Asset owners, OT/industrial security teams, and vulnerability managers responsible for systems referenced in Siemens ProductCERT advisory SSA-770770 / CISA ICSA-25-044-06 should review this immediately. Teams that rely on API-key plus certificate-based authentication should also verify whether any exposed assets match the CVE description or the Siemens product tree, because the source data is conflicting.

Technical summary

The CVE record describes a missing authentication step that may let an API user authenticate using api-key plus PKI user certificate authentication even when the certificate is invalid. The CVSS vector supplied in the source indicates network reachability with high privileges required (CVSS 3.1 vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), yielding a 7.2 HIGH score. The source corpus also contains a product/vendor mismatch: the vulnerability text refers to Fortinet products, while the CSAF advisory maps the issue to Siemens RUGGEDCOM APE1808.

Defensive priority

High for environments using certificate-based API authentication, but remediation should be gated by source verification because the affected product mapping is inconsistent. Confirm the exact asset population first, then apply vendor guidance and update controls for certificate validation and API access.

Recommended defensive actions

  • Cross-check affected assets against both the CVE text and the Siemens CSAF product tree before scheduling remediation.
  • Use the official Siemens ProductCERT advisory SSA-770770 and CISA ICSA-25-044-06 to confirm the correct fix and affected versions.
  • Validate whether any API users rely on api-key plus certificate authentication and review certificate validation logic and access control.
  • Apply vendor-recommended updates or mitigations only after confirming the correct product mapping; do not rely on the conflicting remediation text without verification.
  • Review authentication logs for unexpected API login activity and investigate any successful logins that used invalid or expired certificates.
  • Update vulnerability-management records to reflect the source-data conflict so follow-up remediation targets the correct platform.

Evidence notes

Published date used for timing context: 2025-02-11. The source item was later republished/updated on 2026-03-12, with a note that the update was based on Siemens ProductCERT advisory SSA-770770. The corpus conflicts in multiple places: the CVE description names Fortinet FortiOS/FortiProxy versions, the CSAF advisory and affected product tree list Siemens RUGGEDCOM APE1808, and the remediation field references Fortigate NGFW V7.4.7. Because of these inconsistencies, the safest interpretation is that the record must be verified directly against the official vendor references before operational use.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-52965 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-52965

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-52965 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-52965

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-770770.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-770770.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.