CISA

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

From Cybersecurity and Infrastructure Security Agency ↗

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected:

RUGGEDCOM APE1808 vers:all/* 

Vendor

Equipment

Siemens

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company Headquarters Location...