PatchSiren cyber security CVE debrief
CVE-2025-4230 Siemens CVE debrief
CVE-2025-4230 is a medium-severity command injection issue disclosed in the CISA/Siemens CSAF advisory on 2025-06-10 and republished on 2026-03-12. The supplied corpus says exploitation requires an authenticated administrator with access to the PAN-OS CLI, and the impact is arbitrary command execution as root. The advisory metadata, however, identifies Siemens RUGGEDCOM APE1808 as the affected product, so defenders should treat the source set as containing a product/description mismatch and verify the exact affected platform before acting.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-03-12
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-03-12
Who should care
OT/ICS administrators and security teams responsible for Siemens RUGGEDCOM APE1808, especially environments that grant CLI access to authenticated administrators. Also relevant to teams that manage privileged access controls, vendor advisory tracking, and change control for industrial appliances.
Technical summary
The vulnerability is described as command injection with local attack conditions and high privileges required (CVSS 3.1 vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). In the supplied text, an authenticated administrator with CLI access can bypass system restrictions and run arbitrary commands as root. This is not presented as a remote, unauthenticated flaw; the practical exposure hinges on how broadly administrative CLI access is granted and whether privileged access is tightly controlled.
Defensive priority
Medium priority. Focus first on systems where administrative CLI access is exposed to a broad operator set, shared accounts exist, or privileged access controls are weak.
Recommended defensive actions
- Restrict CLI access to a limited group of trusted administrators.
- Review and remove unnecessary administrative accounts or shared credentials that can reach the CLI.
- Contact Siemens customer support for patch and update guidance for the affected product.
- Apply vendor fixes as soon as they are available, using normal OT change-management procedures.
- Monitor administrative activity for unusual CLI use and investigate unexpected command execution or privilege escalation attempts.
Evidence notes
Source item: CISA CSAF ICSA-25-162-02 (published 2025-06-10; modified 2026-03-12). The revision history shows later republication based on Siemens ProductCERT SSA-513708. The corpus contains an internal inconsistency: the advisory metadata names Siemens RUGGEDCOM APE1808, while the vulnerability description states Palo Alto Networks PAN-OS CLI command injection. This debrief preserves both facts and flags the mismatch for verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-4230 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-4230
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-4230 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-4230
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-513708.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-513708.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.