PatchSiren cyber security CVE debrief
CVE-2024-5918 Siemens CVE debrief
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you 'Allow Authentication with User Credentials OR Client Certificate.'
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2025-05-13
- Advisory published
- 2024-04-09
- Advisory updated
- 2025-05-13
Who should care
Organizations using Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW, particularly those with GlobalProtect deployments using client certificate authentication. Industrial control system operators should prioritize this fix given the critical infrastructure context.
Technical summary
CVE-2024-5918 is an improper certificate validation vulnerability in Palo Alto Networks PAN-OS software. When GlobalProtect is configured to 'Allow Authentication with User Credentials OR Client Certificate,' an authorized attacker can use a specially crafted client certificate to authenticate as a different legitimate user. This affects Siemens RUGGEDCOM APE1808 devices configured with Palo Alto Networks Virtual NGFW. The vulnerability has a CVSS 3.1 score of 7.4 (HIGH). A vendor fix is available by upgrading to Palo Alto Networks Virtual NGFW V11.1.2-h3.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Palo Alto Networks Virtual NGFW to V11.1.2-h3. Contact customer support to receive patch and update information.
- Review GlobalProtect authentication configuration and disable 'Allow Authentication with User Credentials OR Client Certificate' if not required.
- Validate client certificate authentication implementations to ensure proper certificate chain validation and subject verification.
- Monitor GlobalProtect portal and gateway logs for anomalous authentication patterns or certificate-based access attempts.
- Apply defense-in-depth controls for industrial control systems per CISA recommended practices.
Evidence notes
CVE published 2024-04-09; modified 2025-05-13. CISA CSAF advisory ICSA-24-102-04 tracks this vulnerability for Siemens RUGGEDCOM APE1808 devices configured with Palo Alto Networks Virtual NGFW. The advisory was updated on 2024-12-10 to add CVE-2024-5918 as a newly published upstream vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-5918 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-5918
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-5918 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-5918
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-102-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-455250.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-455250.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.