PatchSiren cyber security CVE debrief
CVE-2025-3719 Siemens CVE debrief
An access control vulnerability in the CLI functionality of Siemens RUGGEDCOM APE1808 allows authenticated users with limited privileges to bypass intended restrictions and execute administrative commands. This improper authorization flaw, published 2025-08-12, enables privilege escalation with network-based attack vectors requiring only low-privileged authentication. The vulnerability carries HIGH severity (CVSS 8.1) with significant integrity and availability impact potential, as attackers can alter device configurations or disrupt operations. The affected product is an industrial networking device commonly deployed in critical infrastructure environments. Remediation requires upgrading to Nozomi Guardian/CMC V25.4.0, with CLI-based upgrade recommended due to potential Web GUI errors during the process.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-01-14
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-01-14
Who should care
Organizations operating Siemens RUGGEDCOM APE1808 devices in industrial and critical infrastructure environments, particularly those with multi-user CLI access configurations. Security teams responsible for ICS/OT network segmentation and access control should prioritize this vulnerability due to its HIGH severity and potential for operational disruption.
Technical summary
The vulnerability exists in the command-line interface (CLI) functionality where a specific access restriction is not properly enforced for users with limited privileges. Authentication is required, but once authenticated, low-privilege users can issue administrative CLI commands that should be restricted. The attack vector is network-accessible with low attack complexity. The vulnerability results in no confidentiality impact but high integrity and availability impact, as attackers can modify device configurations or affect system availability. The fix involves upgrading to Nozomi Guardian/CMC V25.4.0, with vendor support contact required for patch acquisition.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Nozomi Guardian/CMC to V25.4.0 using CLI method due to potential Web GUI errors during upgrade process
- Implement internal firewall rules to restrict access to the web management interface
- Audit and remove unnecessary accounts with web management interface access
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
- Monitor CLI access logs for unauthorized administrative command execution by non-privileged accounts
Evidence notes
CVE description and CISA CSAF advisory ICSA-25-226-09 confirm CLI access control bypass allowing limited-privilege users to execute administrative commands. CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H sourced from advisory. Vendor fix specified as upgrade to V25.4.0 with CLI upgrade method recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-3719 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-3719
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-3719 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3719
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-978177.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-978177.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.