Siemens RUGGEDCOM APE1808
View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures. The following versions of Siemens RUGGEDCOM APE1808 are affected: RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens RUGGEDCOM APE1808 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-23573 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests. View CVE Details Affected Products Siemens RUGGEDCOM APE1808 Vendor: Siemens Product Version: RUGGEDCOM APE1808 with Fortinet NGFW Product Status: known_affected Remediations Vendor fix Contact customer support to receive detailed information Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2026-59839 An Improper Limitation of a Pathna
CSIRTS triage
- What
- Cross-site scripting and path traversal vulnerabilities in the device web interface based on FortiOS vulnerabilities.
- Who is affected
- All versions of Siemens RUGGEDCOM APE1808 in critical manufacturing, energy, and transportation critical infrastructure worldwide.
- Urgency
- Important; CVSS 6.1 with web-based attack surface; reference Fortinet advisory for details and workarounds.
- Action
- Contact Siemens customer support and follow Fortinet advisory for mitigation measures and updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch RUGGEDCOM APE1808
Get an email when a new RUGGEDCOM APE1808 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-235730.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598390.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-23573 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59839 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0282 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl
- medium[NEW] [medium] Fortinet FortiOS and FortiProxy: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis
- mediumCVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability…nvd
- mediumCVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulner…nvd
- unknownPath traversal in CLI command allows deletion of root file systemfortinet
- unknownSSL-VPN Reflected XSSfortinet
Recent advisories for Siemens RUGGEDCOM APE1808
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWcisa · 2026-07-21
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13