PatchSiren cyber security CVE debrief
CVE-2025-1501 Siemens CVE debrief
An access control vulnerability in the Request Trace and Download Trace functionalities of CMC before 25.1.0 allows authenticated users with limited privileges to request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. The vulnerability was published on 2025-08-12 and last modified on 2026-01-14. Siemens has released a vendor fix in version 25.4.0 of Nozomi Guardian / CMC.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-01-14
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-01-14
Who should care
Organizations operating Siemens RUGGEDCOM APE1808 devices with CMC versions prior to 25.1.0, particularly those in industrial control system (ICS) environments where network trace data may contain sensitive operational information. Security teams responsible for access control policies and OT network segmentation should prioritize this fix.
Technical summary
The vulnerability exists in the Request Trace and Download Trace functionalities of CMC (Central Management Console) versions prior to 25.1.0. A specific access restriction is not properly enforced for users with limited privileges, allowing authenticated users to request and download trace files that may contain unauthorized network data. The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction. The confidentiality impact is low with no integrity or availability impact.
Defensive priority
medium
Recommended defensive actions
- Upgrade Nozomi Guardian / CMC to V25.4.0. Note that using the Web GUI may have errors during upgrade; it is recommended to use the CLI. Contact customer support to receive patch and update information.
- Use internal firewall features to limit access to the web management interface.
- Follow CISA ICS recommended practices for defense in depth and network segmentation.
Evidence notes
The vulnerability affects RUGGEDCOM APE1808 with CMC before 25.1.0. CISA republished the Siemens ProductCERT SSA-978177 advisory on 2026-01-14. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N with a score of 4.3 (MEDIUM).
Sources and references
Verified primary and authoritative sources
-
CVE-2025-1501 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-1501
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-1501 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-1501
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-978177.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-978177.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.