Full Report
Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices
## CVE Details
- **CVE ID:** CVE-2026-23573
- **CVSS Score:** 6.1 (Medium)
- **CWE:** CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting)
- **CVE ID:** CVE-2026-59839
- **CVSS Score:** 5.5 (Medium)
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal)
## Affected Systems
- **Products:** RUGGEDCOM APE1808 (Application hosting platform)
- **Versions:** All versions running Fortinet NGFW (Next-Generation Firewall) software.
- **Specific Fortinet Components (Upstream):**
- FortiOS: 7.6.0 through 7.6.6; 7.4 (all); 7.2 (all).
- FortiPAM: 1.0 through 1.8.0.
- FortiProxy: 7.4.0 through 7.4.3; 7.2.0 through 7.2.9.
- FortiSwitch Manager (specific to CVE-2026-59839).
## Vulnerability Description
- **CVE-2026-23573:** A Cross-site Scripting (XSS) flaw exists in the web management interface. An authenticated remote user can execute arbitrary code or commands in the context of the user's browser session via specially crafted requests.
- **CVE-2026-59839:** A Path Traversal vulnerability exists in the Command Line Interface (CLI). A privileged authenticated attacker with physical access to the device can bypass directory restrictions to delete critical system files via crafted CLI commands.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; no PoC specifically mentioned in the Siemens advisory.
- **Complexity:** Low (for both vulnerabilities).
- **Attack Vector:**
- CVE-2026-23573: Network (Requires User Interaction).
- CVE-2026-59839: Physical (Requires high privileges).
## Impact
- **Confidentiality:** Low (CVE-2026-23573); None (CVE-2026-59839).
- **Integrity:** Low (CVE-2026-23573); High (CVE-2026-59839).
- **Availability:** None (CVE-2026-23573); High (CVE-2026-59839 - File system deletion).
## Remediation
### Patches
Siemens has not released a direct firmware update for the APE1808 at this time.
- **Action:** Contact Siemens Customer Support to receive detailed information and specific remediation steps for the RUGGEDCOM APE1808 platform.
### Workarounds
- **Fortinet Upstream Advice:** Follow the official Fortinet PSIRT advisories for specific configuration changes or mitigations related to FortiOS.
- **Access Control:** Restrict physical access to the device to mitigate CVE-2026-59839.
- **General Hardening:** Protect network access to devices with appropriate firewalls and VPNs; follow Siemens' Operational Guidelines for Industrial Security.
## Detection
- **Indicators of compromise:** Monitor for unusual CLI command execution related to file system pathing (e.g., `../`) or suspicious web requests to the management console.
- **Detection methods and tools:** Audit logs for administrative actions and physical access logs to the hosting hardware.
## References
- **Siemens Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/html/ssa-127084[.]html
- **Fortinet PSIRT:** hxxps://www[.]fortiguard[.]com/psirt
- **Fortinet RSS Feed:** hxxps://filestore[.]fortinet[.]com/fortiguard/rss/ir[.]xml
- **Siemens Industrial Security Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security