PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-3719 Siemens CVE debrief

An access control vulnerability in the CLI functionality of Siemens RUGGEDCOM APE1808 allows authenticated users with limited privileges to bypass intended restrictions and execute administrative commands. This improper authorization flaw, published 2025-08-12, enables privilege escalation with network-based attack vectors requiring only low-privileged authentication. The vulnerability carries HIGH severity (CVSS 8.1) with significant integrity and availability impact potential, as attackers can alter device configurations or disrupt operations. The affected product is an industrial networking device commonly deployed in critical infrastructure environments. Remediation requires upgrading to Nozomi Guardian/CMC V25.4.0, with CLI-based upgrade recommended due to potential Web GUI errors during the process.

Vendor
Siemens
Product
RUGGEDCOM APE1808
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-01-14
Advisory published
2025-08-12
Advisory updated
2026-01-14

Who should care

Organizations operating Siemens RUGGEDCOM APE1808 devices in industrial and critical infrastructure environments, particularly those with multi-user CLI access configurations. Security teams responsible for ICS/OT network segmentation and access control should prioritize this vulnerability due to its HIGH severity and potential for operational disruption.

Technical summary

The vulnerability exists in the command-line interface (CLI) functionality where a specific access restriction is not properly enforced for users with limited privileges. Authentication is required, but once authenticated, low-privilege users can issue administrative CLI commands that should be restricted. The attack vector is network-accessible with low attack complexity. The vulnerability results in no confidentiality impact but high integrity and availability impact, as attackers can modify device configurations or affect system availability. The fix involves upgrading to Nozomi Guardian/CMC V25.4.0, with vendor support contact required for patch acquisition.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Nozomi Guardian/CMC to V25.4.0 using CLI method due to potential Web GUI errors during upgrade process
  • Implement internal firewall rules to restrict access to the web management interface
  • Audit and remove unnecessary accounts with web management interface access
  • Apply defense-in-depth strategies for industrial control systems per CISA guidance
  • Monitor CLI access logs for unauthorized administrative command execution by non-privileged accounts

Evidence notes

CVE description and CISA CSAF advisory ICSA-25-226-09 confirm CLI access control bypass allowing limited-privilege users to execute administrative commands. CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H sourced from advisory. Vendor fix specified as upgrade to V25.4.0 with CLI upgrade method recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-3719 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-3719

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-3719 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3719

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-978177.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-978177.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.