www.cisa.gov 5/19/2026, 6:01:14 PM · via preferred

Siemens RUGGEDCOM APE1808 Devices

Siemens RUGGEDCOM APE1808 Devices

According to Siemens ProductCERT, a buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The following versions of…

First seen 2026-05-06T05:01:14.381Z · Last seen 2026-05-19T18:01:14.899Z

CyberSIXT Evidence Panel
Primary Source cve.org
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to Siemens ProductCERT, a buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The following versions of Siemens RUGGEDCOM APE1808 Devices are affected: vers:all/* (CVE-2026-0300), with CVSS v3.1 base score 10 and base severity CRITICAL.

Siemens is preparing fix versions and recommends countermeasures; customers should consult and implement the workarounds in Palo Alto Networks’ upstream security notifications. The advisory notes worldwide deployment of the Siemens RUGGEDCOM APE1808 Devices and identifies the vulnerability as a known-affected product.

Recommended mitigations include disabling Response Pages in the Interface Management Profile on every L3 interface in zones where untrusted traffic can ingress, disabling the User-ID Authentication Portal if not required, and restricting access to the portal to trusted internal IP addresses only. The release date is listed as 19 May 2026.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline