Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

MonitorCVSS 7.2ICS-CERT ICSA-26-202-02Jul 14, 2026
SiemensPalo Alto NetworksManufacturing
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities exist in Palo Alto Networks PAN-OS running on Siemens RUGGEDCOM APE1808 industrial firewalls. The vulnerabilities allow authenticated attackers with high privileges to execute arbitrary code on the device, potentially affecting network security controls for industrial systems. CWEs include improper input validation (CWE-79), missing authorization checks (CWE-862), and OS command injection (CWE-78).

What this means
What could happen
An attacker with high-level privileges could execute arbitrary code on the RUGGEDCOM APE1808 firewall, potentially disrupting network traffic routing for manufacturing control systems or exfiltrating sensitive operational data.
Who's at risk
Manufacturing facilities and industrial plants using Siemens RUGGEDCOM APE1808 industrial firewalls with embedded Palo Alto Networks Virtual NGFW for network protection and traffic filtering.
How it could be exploited
An attacker with administrative credentials on the PAN-OS Virtual NGFW could inject malicious code through the web interface or management API to execute commands on the firewall. This could allow them to modify network policies, intercept communications, or redirect traffic from industrial control devices to attacker-controlled systems.
Prerequisites
  • Administrative or equivalent high-privilege credentials on the PAN-OS management interface
  • Network access to the PAN-OS management interface (typically port 443)
remotely exploitablehigh CVSS score (7.2)requires high-level credentialsaffects network infrastructureno specific patch version published yet
Exploitability
Some exploitation risk — EPSS score 1.3%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (1)
ProductAffected VersionsFix Status
RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/3
WORKAROUNDRestrict administrative access to the PAN-OS management interface to authorized engineering workstations only using firewall rules or network segmentation.
HARDENINGDisable remote management of the PAN-OS Virtual NGFW if not required for your operational workflow, or require VPN authentication for all management access.
HARDENINGReview and enforce strong, unique passwords for all administrative accounts on the PAN-OS management interface.
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXContact Palo Alto Networks and Siemens support to obtain the latest security patches and firmware updates for your RUGGEDCOM APE1808 devices.
API: /api/v1/advisories/d714c281-e5b4-42ca-8bbf-2b96cbcf26d0

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.