Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices (CVE-2024-13089, CVE-2024-13090, CVE-2025-3719, CVE-2025-40889, et al.)

Multiple Vulnerabilities in Nozomi Guardian/CMC Before (TL-2026-2487), also tracked as SSA-978177, is a high-severity software vulnerability scored CVSS 8.1, first published 2026-09-13. It has no confirmed attribution, affects Siemens RUGGEDCOM APE1808, references 11 CVEs (CVE-2024-13089, CVE-2024-13090, CVE-2025-1501), maps to 10 MITRE ATT&CK techniques (T1005, T1059.004, T1059.007), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2487

Threat ID
TL-2026-2487
Also known as
SSA-978177, ICSA-25-226-09
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-13
Last reviewed
2026-09-13
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
critical manufacturing
Target regions
Worldwide
Detection rules
9
Indicators of compromise
10

Siemens ProductCERT advisory SSA-978177 (CISA ICSA-25-226-09) discloses eleven CVEs affecting Nozomi Guardian/CMC prior to version 25.4.0 running on RUGGEDCOM APE1808 industrial edge computing appliances, spanning OS command injection, sudo-based privilege escalation, access-control bypass, SQL injection, path traversal, and stored/reflected cross-site scripting. All eleven have vendor-released fixes and none is known to be publicly exploited or to have a public PoC.

How Multiple Vulnerabilities in Nozomi Guardian/CMC Before works

Nozomi Networks disclosed eleven vulnerabilities in its Guardian and Central Management Console (CMC) OT network-monitoring software between June 2025 and November 2025 via its PSIRT portal (security.nozominetworks.com). Because Siemens embeds Guardian/CMC as the OT-monitoring stack on its RUGGEDCOM APE1808 industrial edge-computing appliance, Siemens ProductCERT republished the set as SSA-978177 (first published 2025-08-12, updated to v1.3 on 2026-01-13 to add the final CVE), and CISA mirrored it as ICS advisory ICSA-25-226-09 (2025-08-14) for the Critical Manufacturing sector, worldwide.

The most severe issues are CVE-2024-13089 (CVSS 3.1 7.2 / CWE-78), where an authenticated administrator can bypass improper signature validation in the Guardian/CMC update mechanism to execute arbitrary OS commands via a crafted update package, and CVE-2024-13090 (CVSS 3.1 7.0 / CWE-250), where a local service account was configured with excessively permissive sudo rules, letting an attacker who compromises that account escalate to administrative control. Both were fixed in 24.6.0.

A second cluster, published 2025-10-07, covers CVE-2025-3719 (CVSS 3.1 8.1 / CWE-863) — an incorrect-authorization flaw in the CLI that lets a limited-privilege authenticated user issue administrative commands and alter device configuration — and CVE-2025-40889 (CVSS 3.1 8.1 / CWE-22), a path-traversal bug in the Time Machine feature caused by missing validation of two input parameters, letting a limited-privilege user alter the structure/content of files under /data or affect their availability. The same batch adds four authenticated SQL-injection flaws (CWE-89) in the Alert, Smart Polling, and CLI functionality (CVE-2025-40885, CVE-2025-40886 [CVSS 3.1 8.8, the highest raw score in the set], CVE-2025-40887, CVE-2025-40888) that let a limited-privilege user run arbitrary SELECT (and, for 40886, broader) SQL statements against the application's DBMS, and a client-side path-traversal/XSS flaw in the web front-end (CVE-2025-3718, CWE-22) triggerable by a crafted URL visited by an authenticated victim. CVE-2025-1501 (CVSS 3.1 4.3 / CWE-863, published 2025-08-26, fixed in CMC 25.1.0) is a lower-severity access-control gap letting a limited-privilege user request and download network trace files they should not have access to.

The final and most recently added issue, CVE-2025-40890 (CVSS 3.1 7.9 / CWE-79, published 2025-11-25, fixed in 25.4.0), is a stored XSS in the Dashboards feature: a low-privilege authenticated user can craft a dashboard containing a JavaScript payload and share it, executing in the browser session of any victim who views or imports it.

No individual CVE requires unauthenticated network access (all but the two 2024 CVEs require an existing low- or limited-privilege account), and CISA states no known public exploitation has been reported for any of them; no public proof-of-concept exists for the set. Because the flaws sit across privilege escalation (3719, 13090), data-store access (the SQLi cluster), and file/dashboard integrity (40889, 40890), an attacker who first obtains a low-privilege Guardian/CMC account — e.g. via credential reuse or a phished session — could plausibly chain them to reach administrative CLI control, exfiltrate alerting/asset data from the DBMS, and tamper with stored monitoring artifacts, which is significant given Guardian/CMC's role as the OT visibility and alerting layer on RUGGEDCOM APE1808 deployments. Siemens recommends upgrading to Guardian/CMC 25.4.0 via the CLI, noting the Web GUI upgrade path may error.

MITRE ATT&CK techniques used in TL-2026-2487

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Execution

T1059.004 Unix Shell; T1059.007 JavaScript; T1204.002 Malicious File

Privilege Escalation

T1078.003 Local Accounts; T1548.003 Sudo and Sudo Caching

Initial Access

T1190 Exploit Public-Facing Application

defense-impairment

T1553 Subvert Trust Controls

Impact

T1565.001 Stored Data Manipulation

Affected products and versions in Multiple Vulnerabilities in Nozomi Guardian/CMC Before

  • Siemens — RUGGEDCOM APE1808
    Vulnerable versions: All versions running Nozomi Guardian/CMC before V25.4.0
    Fixed in: Nozomi Guardian/CMC V25.4.0 (apply via CLI; Web GUI upgrade path may error)
  • Nozomi Networks — Guardian
    Vulnerable versions: < 24.6.0; < 25.1.0; < 25.2.0; < 25.3.0; < 25.4.0
    Fixed in: 25.4.0
  • Nozomi Networks — CMC (Central Management Console)
    Vulnerable versions: < 24.6.0; < 25.1.0; < 25.2.0; < 25.3.0; < 25.4.0
    Fixed in: 25.4.0

Remediation for Multiple Vulnerabilities in Nozomi Guardian/CMC Before

Patches

  • Nozomi Guardian/CMC V25.4.0 (Siemens SSA-978177 recommended target version)
  • Guardian/CMC 24.6.0 fixes CVE-2024-13089 and CVE-2024-13090
  • Guardian/CMC 25.1.0 fixes CVE-2025-1501
  • Guardian/CMC 25.2.0 fixes CVE-2025-3718, CVE-2025-3719, CVE-2025-40885, CVE-2025-40886, CVE-2025-40887, CVE-2025-40889
  • Guardian/CMC 25.3.0 fixes CVE-2025-40888
  • Guardian/CMC 25.4.0 fixes CVE-2025-40890

Immediate actions

  • Upgrade Nozomi Guardian/CMC on all affected RUGGEDCOM APE1808 devices to V25.4.0, applying the update via the CLI (Siemens notes the Web GUI upgrade path may error)
  • Restrict access to the Guardian/CMC web management interface and CLI to trusted management networks using internal firewall rules / network segmentation
  • Audit and remove unnecessary user accounts that have access to the web or CLI interfaces, and review the sudoers configuration for local service accounts
  • Only install Guardian/CMC update packages obtained from trusted, verified sources

Workarounds

  • Restrict web management interface and CLI access via network-based access control until the upgrade is applied
  • Exercise caution with untrusted links and shared/imported dashboards while authenticated to Guardian/CMC

Longer-term hardening

  • Apply least-privilege to service-account sudoers entries and periodically audit sudo configuration on Guardian/CMC hosts
  • Use VPNs or equivalent for any necessary remote administrative access to RUGGEDCOM APE1808 devices
  • Monitor CLI and web-interface authentication/authorization logs for anomalous privilege-escalation, SQL-error, or path-traversal attempts
  • Follow Siemens' Operational Guidelines for Industrial Security and keep ICS/OT monitoring networks segmented from business IT and the Internet

CVEs associated with Multiple Vulnerabilities in Nozomi Guardian/CMC Before

CVE-2024-13089, CVE-2024-13090, CVE-2025-1501, CVE-2025-3718, CVE-2025-3719, CVE-2025-40885, CVE-2025-40886, CVE-2025-40887, CVE-2025-40888, CVE-2025-40889, CVE-2025-40890

Weaknesses (CWE) in Multiple Vulnerabilities in Nozomi Guardian/CMC Before

CWE-78, CWE-250, CWE-863, CWE-22, CWE-89, CWE-79

Timeline of Multiple Vulnerabilities in Nozomi Guardian/CMC Before

  • Nozomi Networks PSIRT publishes NN-2025:1-01 (CVE-2024-13089, OS command injection via improper update-signature validation) and NN-2025:2-01 (CVE-2024-13090, sudo privilege escalation); both fixed in Guardian/CMC 24.6.0.
  • Siemens ProductCERT publishes SSA-978177 v1.0, republishing the Nozomi Guardian/CMC vulnerabilities for RUGGEDCOM APE1808 devices.
  • CISA republishes the advisory as ICS advisory ICSA-25-226-09 for the Critical Manufacturing sector, noting worldwide deployment and no known public exploitation.
  • Nozomi Networks publishes NN-2025:3-01 (CVE-2025-1501, improper access control letting a limited-privilege user download network trace files); fixed in CMC 25.1.0.
  • Nozomi Networks publishes seven CVEs in one batch: CVE-2025-3718 (client-side path traversal/XSS), CVE-2025-3719 (CLI authorization bypass, CVSS 8.1), CVE-2025-40885/40886/40887 (SQL injection in Smart Polling/Alert), CVE-2025-40888 (SQL injection in CLI), and CVE-2025-40889 (path traversal in Time Machine, CVSS 8.1); fixed across Guardian/CMC 25.2.0 (all but 40888) and 25.3.0 (40888).
  • Nozomi Networks publishes NN-2025:11-01 (CVE-2025-40890, stored XSS via a shared/imported malicious dashboard); fixed in Guardian/CMC 25.4.0, the version Siemens now recommends for RUGGEDCOM APE1808.
  • Siemens updates SSA-978177 to v1.3, adding CVE-2025-40890 to the RUGGEDCOM APE1808 advisory.
  • CISA republishes a related but distinct Siemens RUGGEDCOM APE1808 advisory (ICSA-26-015-07) covering four additional Nozomi-inherited CVEs (CVE-2025-40891/40892/40893/40898), showing continued disclosure activity for this OT network-monitoring platform outside the scope of SSA-978177's eleven CVEs.

Sources cited for Multiple Vulnerabilities in Nozomi Guardian/CMC Before

More in vulnerability

Detection coverage for TL-2026-2487

As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2487 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats