PatchSiren cyber security CVE debrief
CVE-2025-1501 Siemens CVE debrief
An access control vulnerability in the Request Trace and Download Trace functionalities of CMC before 25.1.0 allows authenticated users with limited privileges to request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. The vulnerability was published on 2025-08-12 and last modified on 2026-01-14. Siemens has released a vendor fix in version 25.4.0 of Nozomi Guardian / CMC.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-01-14
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-01-14
Who should care
Organizations operating Siemens RUGGEDCOM APE1808 devices with CMC versions prior to 25.1.0, particularly those in industrial control system (ICS) environments where network trace data may contain sensitive operational information. Security teams responsible for access control policies and OT network segmentation should prioritize this fix.
Technical summary
The vulnerability exists in the Request Trace and Download Trace functionalities of CMC (Central Management Console) versions prior to 25.1.0. A specific access restriction is not properly enforced for users with limited privileges, allowing authenticated users to request and download trace files that may contain unauthorized network data. The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction. The confidentiality impact is low with no integrity or availability impact.
Defensive priority
medium
Recommended defensive actions
- Upgrade Nozomi Guardian / CMC to V25.4.0. Note that using the Web GUI may have errors during upgrade; it is recommended to use the CLI. Contact customer support to receive patch and update information.
- Use internal firewall features to limit access to the web management interface.
- Follow CISA ICS recommended practices for defense in depth and network segmentation.
Evidence notes
The vulnerability affects RUGGEDCOM APE1808 with CMC before 25.1.0. CISA republished the Siemens ProductCERT SSA-978177 advisory on 2026-01-14. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N with a score of 4.3 (MEDIUM).
Official resources
-
CVE-2025-1501 CVE record
CVE.org
-
CVE-2025-1501 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12