{"uid":"cap_J2V-z_aqzSlQv4tba83sx","slug":"ot-intel-api-onrender-com-06cd9925","name":"OT/ICS Patch Feasibility Assessment API","description":"OT/ICS patch feasibility for a CVE. Pass ?id=CVE-XXXX-XXXX. Returns patch availability, OT-safe workarounds, patch complexity per ICS layer, estimated downtime, safe-to-patch-live flag, deployment strategy, and risk-vs-disruption score 1-10.","url":"https://ot-intel-api.onrender.com/ot/patch","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["id"],"properties":{"id":{"type":"string","description":"CVE identifier e.g. CVE-2021-34527"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"cve_id":"CVE-2021-34527","severity":"HIGH","freshness":"2025-05-22T10:00:00.000Z","cvss_score":8.8,"workarounds":["Disable the Print Spooler service on OT systems where printing is not required","Block inbound SMB (port 445) at the IT/OT DMZ firewall"],"data_sources":["NVD","CISA-KEV","DeepSeek-CTI-Analysis"],"ot_feasibility":{"requires_reboot":true,"patch_complexity":"Medium","recommended_window":"Scheduled maintenance window","safe_to_patch_live":false,"deployment_strategy":"Apply during planned outage. Test on non-production SCADA node first.","estimated_downtime_minutes":30},"patch_available":true,"vendor_advisories":[{"tags":["Patch","Vendor Advisory"],"advisory_url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527"}],"actively_exploited":true,"risk_vs_disruption":{"score":9,"rationale":"In CISA KEV — actively exploited. Patch urgently despite downtime required."}}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"cve_id":"CVE-2021-22941"}}},"response":{"_note":"Pass ?id=CVE-YYYY-NNNNN for a real patch feasibility assessment","data_sources":["NVD","CISA-KEV","DeepSeek-CTI-Analysis"]}},"exampleRequest":{"cve_id":"CVE-2021-22941"},"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_JrfLpnaP0fGV9KI7dTALO","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns OT-safe patch feasibility analysis for a given CVE ID, including patch availability, vendor advisories, workarounds, downtime estimates, CISA KEV status, and a risk-vs-disruption score tailored for ICS/SCADA environments.","exampleAgentPrompt":"Can you assess the patch feasibility for CVE-2021-22941 in an OT/ICS environment — I need to know if it's safe to patch live, how long the downtime would be, whether it's in the CISA KEV list, and what the risk-vs-disruption score is?","exampleUseCases":null,"resultDescription":"Returns a structured JSON object containing: patch availability status (from NVD references), vendor advisory URLs, OT-safe workarounds if patching is disruptive, patch complexity for the affected ICS layer, estimated downtime in minutes, a boolean indicating whether it is safe to patch on a live system, recommended maintenance window, deployment strategy, CISA KEV status, and a 1–10 risk-vs-disruption score with rationale. All enriched via DeepSeek AI.","failureModes":["Missing or malformed CVE ID returns an error or empty result","CVE not found in NVD returns limited or null patch availability data","Render.com cold start may add latency on first request","DeepSeek enrichment failure may result in partial or degraded response","Very recent CVEs may lack NVD references or vendor advisory data"],"whenToPreferThis":"Use this endpoint when you need OT/ICS-specific patch guidance for a CVE — not just generic CVSS scores. It is uniquely suited for operational technology environments where patching a live system may cause physical disruption, and where standard IT patch guidance is insufficient. Prefer this over generic CVE lookup APIs when you need downtime estimates, safe-to-patch-live assessments, maintenance window recommendations, and ICS-layer-specific complexity ratings.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:43:18.406Z","isFirstParty":false}