Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Summary
Palo Alto Networks has identified vulnerabilities in PAN-OS software, impacting Siemens RUGGEDCOM APE1808 devices running their Virtual NGFW. The vulnerabilities include cross-site scripting, missing authorization, and OS command injection. Customers are advised to consult Palo Alto Networks' advisories for workarounds and remediation.
IFF Assessment
The article details several vulnerabilities in critical network infrastructure, posing a risk to defenders by highlighting potential attack vectors.
Severity
The CVSS score of 7.2 reflects the severity of the identified vulnerabilities, which include cross-site scripting and OS command injection, allowing for potential unauthorized access and control.
Defender Context
Defenders need to be aware of these vulnerabilities affecting industrial control systems (ICS) and critical infrastructure. Prompt patching or implementation of workarounds provided by Palo Alto Networks is crucial to prevent exploitation, particularly given the worldwide deployment and critical manufacturing sector involvement.