Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Palo Alto Networks has identified vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include cross-site scripting, privilege escalation, and command injection, all of which could allow an attacker to execute arbitrary commands and compromise the device. Siemens ProductCERT reported these vulnerabilities to CISA. Customers are advised to contact customer support for patch and update information.
Palo Alto Networks has published information on vulnerabilities in PAN-OS software that impact Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include a cross-site scripting (XSS) vulnerability, a privilege escalation vulnerability, and a command injection vulnerability. The XSS vulnerability allows a malicious authenticated administrator to store a JavaScript payload, while the privilege escalation and command injection vulnerabilities enable an attacker to bypass system restrictions and run arbitrary commands as a root user, provided they have access to the PAN-OS CLI or Web UI. Siemens ProductCERT reported these vulnerabilities to CISA.
Affected Products: Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW and Siemens.
Remediation: Contact customer support to receive patch and update information.
Relevant CWEs: CWE-79 (Improper Neutralization of Input During Web Page Generation - Cross-site Scripting), CWE-862 (Missing Authorization), CWE-78 (Improper Neutralization of Special Elements used in an OS Command - OS Command Injection).
General Recommendations: Siemens strongly recommends protecting network access to devices with appropriate mechanisms and configuring the environment according to Siemens' operational guidelines for Industrial Security. Additional information on Industrial Security by Siemens can be found at https://www.siemens.com/industrialsecurity.
Additional Resources: For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories