PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0114 Siemens CVE debrief

A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway. The vulnerability was published on July 9, 2024, and most recently modified on January 14, 2026. It carries a CVSS 3.1 score of 5.9 (MEDIUM severity). The vulnerability affects Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW.

Vendor
Siemens
Product
RUGGEDCOM APE1808
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-09
Original CVE updated
2026-01-14
Advisory published
2024-07-09
Advisory updated
2026-01-14

Who should care

Organizations operating Siemens RUGGEDCOM APE1808 devices with Palo Alto Networks Virtual NGFW, particularly in industrial and critical infrastructure environments. Security teams responsible for OT/ICS network protection and availability of remote access VPN services.

Technical summary

CVE-2025-0114 is a Denial of Service vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software. An unauthenticated attacker can exploit this vulnerability by sending a large number of specially crafted packets over time to render the GlobalProtect portal and gateway services unavailable. The vulnerability has a CVSS 3.1 score of 5.9 (MEDIUM) with the vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, and high availability impact. The vulnerability affects Siemens RUGGEDCOM APE1808 industrial devices running Palo Alto Networks Virtual NGFW. A vendor fix is available in Virtual NGFW V11.1.4-h1.

Defensive priority

medium

Recommended defensive actions

  • Upgrade Palo Alto Networks Virtual NGFW to version V11.1.4-h1. Contact customer support to receive patch and update information.
  • Configure network segmentation to restrict access to GlobalProtect portal and gateway interfaces from untrusted networks.
  • Monitor for anomalous traffic patterns targeting GlobalProtect services, particularly high volumes of specially crafted packets.
  • Apply defense-in-depth strategies for industrial control systems as recommended by CISA.

Evidence notes

CVE published 2024-07-09; modified 2026-01-14. Advisory ICSA-24-193-11 republished by CISA on 2026-01-14 as republication of Siemens ProductCERT SSA-364175. CVSS 3.1 vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-0114 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-0114

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-0114 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0114

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-11.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-364175.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-364175.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-11

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.