ICSA-26-139-02
·
Published 2026-07-02
·
View on CISA ICS-CERT ↗
Siemens RUGGEDCOM APE1808 Devices
CVSS 10.0
CRITICAL
CISA KEV — Known Exploited
Risk Summary
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
CVEs (8)
Remediations
- Contact customer support to receive patch and update information
- Disable Authentication Override options (for generating and accepting cookies) in the GlobalProtect portal and gateway configuration
- Use a dedicated certificate for Authentication Override cookies
- Disable the DNS Proxy feature (Network > DNS Proxy) if it is not being used and configure DNS server with a RFC1918 or a public trusted IP address
- Disassociate DNS Proxy from externally accessible interfaces and configure DNS server with a RFC1918 or a public trusted IP address
- Disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress. Keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress
- Disable User-ID™ Authentication Portal if not required
- Restrict access to the User-ID Authentication Portal to trusted internal IP addresses only
Affected Vendors
Siemens
Affected Products (6)
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Siemens
·
RUGGEDCOM APE1808
vers:all/*
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more