Siemens RUGGEDCOM APE1808

MonitorCVSS 6.1ICS-CERT ICSA-26-225-06Aug 11, 2026
SiemensFortinetManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Multiple vulnerabilities exist in the Fortinet NGFW component integrated into Siemens RUGGEDCOM APE1808 devices. These include cross-site scripting (CWE-79) in the web management interface and path traversal (CWE-22) that could allow unauthorized file access. The vulnerabilities affect all versions of RUGGEDCOM APE1808 with Fortinet NGFW.

What this means
What could happen
An attacker could inject malicious scripts into web interfaces or access files outside intended directories on the RUGGEDCOM APE1808, potentially compromising device management and network traffic visibility.
Who's at risk
Manufacturing facilities using Siemens RUGGEDCOM APE1808 appliances with Fortinet NGFW components for network security and traffic inspection. This affects organizations relying on these devices for industrial network perimeter defense and secure remote access to critical infrastructure.
How it could be exploited
An attacker with network access to the RUGGEDCOM APE1808's web management interface could inject malicious JavaScript code (CWE-79) or access restricted files (CWE-22) through the Fortinet NGFW component. This requires the victim to interact with the malicious interface or the attacker to chain the vulnerabilities with other attack vectors.
Prerequisites
  • Network access to the RUGGEDCOM APE1808 web management interface (typically port 80/443)
  • User interaction with a crafted malicious web request (for CWE-79 exploitation)
  • No authentication bypass required for initial exploitation
remotely exploitablelow complexityno authentication requiredaffects network security appliance
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
RUGGEDCOM APE1808 with Fortinet NGFWAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to the RUGGEDCOM APE1808 web management interface using firewall rules; allow only from trusted engineering workstations and administrative networks
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXContact Siemens customer support and Fortinet for available security patches and detailed mitigation guidance
HOTFIXApply Fortinet security updates for FortiOS as they become available through Siemens
Long-term hardening
0/1
HARDENINGDisable or limit access to the web management interface if not actively used for device administration
API: /api/v1/advisories/d8b78e9d-43e9-49e9-a122-cb288c21aa9e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens RUGGEDCOM APE1808 | CVSS 6.1 - OTPulse