{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ofortinetfortipam1.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortipam:1.8.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2026-23573"},{"cvss":5.5,"id":"CVE-2026-59839"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RUGGEDCOM APE1808","FortiOS","FortiPAM","FortiProxy","FortiSwitch Manager"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Siemens","Fortinet"],"content_html":"\u003cp\u003eSiemens has released a security advisory addressing vulnerabilities in the RUGGEDCOM APE1808 appliance, which utilizes Fortinet NGFW technology. The affected software versions within the integration are susceptible to two distinct vulnerabilities identified as CVE-2026-23573 and CVE-2026-59839. CVE-2026-23573 describes a cross-site scripting (XSS) vulnerability that could be leveraged by an authenticated remote user to execute arbitrary code or commands through specifically crafted requests. CVE-2026-59839 is a path traversal vulnerability that permits a privileged, authenticated attacker with physical access to the device to delete the filesystem using crafted CLI commands. These vulnerabilities affect the RUGGEDCOM APE1808 platform globally across energy, transportation, and critical manufacturing sectors. Users are urged to contact Siemens customer support for platform-specific remediation and to consult the original Fortinet advisories for recommended workarounds.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in unauthorized command execution or complete filesystem destruction on the RUGGEDCOM APE1808 appliance. Given the role of these devices in critical infrastructure environments, such disruptions may lead to significant operational instability, loss of control over industrial processes, and loss of device availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eContact Siemens customer support immediately to obtain guidance on patching or mitigating CVE-2026-23573 and CVE-2026-59839 for the RUGGEDCOM APE1808.\u003c/li\u003e\n\u003cli\u003eImplement strict network access control policies to isolate management interfaces of industrial appliances from the internet and unauthorized subnets.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs for unusual CLI activity or suspicious requests directed at the web management interface of the APE1808.\u003c/li\u003e\n\u003cli\u003eEnsure all control system devices are located behind robust firewall solutions and isolated from corporate business networks to mitigate the risk of remote exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:53:34Z","date_published":"2026-08-13T16:53:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ruggedcom-ape1808/","summary":"Siemens RUGGEDCOM APE1808 devices are impacted by multiple vulnerabilities (CVE-2026-23573, CVE-2026-59839) within the integrated Fortinet NGFW software, potentially allowing remote code execution or filesystem deletion.","title":"Vulnerabilities in Siemens RUGGEDCOM APE1808 via Fortinet Integration","url":"https://feed.craftedsignal.io/briefs/2026-08-ruggedcom-ape1808/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:fortinet:fortipam:1.8.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}