Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)

Multiple Fortinet FortiOS Vulnerabilities (incl. (TL-2026-2489), also tracked as SSA-832273, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-13. It has no confirmed attribution, affects Siemens RUGGEDCOM APE1808, references 28 CVEs (CVE-2023-38545, CVE-2023-38546, CVE-2023-44250), maps to 5 MITRE ATT&CK techniques (T1046, T1059, T1190), and is covered by 9 detection rules and 5 indicators of compromise.

Key facts for TL-2026-2489

Threat ID
TL-2026-2489
Also known as
SSA-832273
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-13
Last reviewed
2026-09-13
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
industrial control systems, critical infrastructure, energy, utilities, transport, manufacturing, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
5

Siemens ProductCERT advisory SSA-832273 (rev V2.1, 2026-01-13) lists 28 Fortinet FortiOS/FortiProxy/FortiPAM/FortiSwitchManager CVEs affecting RUGGEDCOM APE1808 OT devices that bundle Fortinet NGFW below V7.4.3. The most severe, CVE-2024-23113, is an unauthenticated remote format-string RCE in the fgfmd daemon (CVSS 9.8) that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-09; the bundle also includes the curl SOCKS5 heap overflow (CVE-2023-38545) and the HTTP/2 Rapid Reset DoS (CVE-2023-44487).

How Multiple Fortinet FortiOS Vulnerabilities (incl. works

SSA-832273 is a Siemens ProductCERT advisory tracking third-party component risk: RUGGEDCOM APE1808 is a Siemens ruggedized application-processing-engine module deployed inside substation, rail, and utility RTU/gateway hardware, and it ships a bundled Fortinet NGFW (FortiOS-based) image below V7.4.3 that inherits 28 upstream Fortinet/curl CVEs. Because the NGFW is an embedded, bundled component rather than a standalone appliance the customer directly patches, the exposure persists on OT devices until Siemens ships (or the operator applies) an updated bundle image, independent of Fortinet's own patch cadence.

The most severe issue, CVE-2024-23113 (CVSS 9.8, CWE-134), is a use of externally-controlled format string in the fgfmd daemon that implements the FortiGate-to-FortiManager (FGFM) management protocol: a remote, unauthenticated attacker reaching the exposed FGFM service can send a crafted packet whose payload is passed unsanitized into a printf-style formatting function, yielding arbitrary code execution. Fortinet disclosed it via FG-IR-24-029; CISA added it to the KEV catalog on 2024-10-09 confirming active exploitation and mandating a three-week remediation window for federal agencies. As of 2024-10-15, Shadowserver reported 87,000+ internet-facing Fortinet devices were still vulnerable.

A second independently critical component is CVE-2023-38545 (CVSS 9.8, CWE-787), a heap buffer overflow in curl's SOCKS5 proxy handshake: when a target hostname exceeds 255 bytes during a slow handshake, an internal name-resolution-mode variable can be mis-set, causing curl to copy the oversized hostname into a fixed-size heap buffer meant for a resolved address. Because FortiOS bundles curl/libcurl, this upstream flaw (patched in curl 8.4.0) is inherited transitively; curl's own advisory lists SSA-832273 among the affected downstream products.

The bundle further includes CVE-2023-44487 (HTTP/2 Rapid Reset, CVSS 7.5), which enabled record-scale DDoS floods against HTTP/2 services worldwide in August-October 2023 by rapidly opening and RST-cancelling streams to exhaust server-side request-processing resources; a cluster of FortiOS/FortiProxy/FortiPAM/FortiSwitchManager CLI format-string bugs (CVE-2023-48784, CVE-2023-36640, CVE-2023-40721, CVE-2023-45583) that let a privileged CLI operator escalate to arbitrary code execution; an SSL-VPN bookmark IDOR (CVE-2024-23112, FG-IR-24-013, CWE-639) letting an authenticated user view another user's stored SSL-VPN bookmarks; an HA-cluster privilege-management flaw (CVE-2023-44250, FG-IR-23-315, CVSS 8.3) and a FortiAuthenticator-HA authentication flaw (CVE-2023-46717, CVSS 8.8) that let a read-only operator escalate to read-write; a missing-authentication flaw affecting the wider Fortinet product family (CVE-2024-26011, FG-IR-24-032, CVSS 9.8); a double-free in JSON object handling (CVE-2023-44247, FG-IR-23-195, CWE-415) reachable via crafted HTTP/HTTPS requests; and a web-cache-poisoning flaw via attacker-controlled Host headers (CVE-2022-23439, CWE-610) across the Fortinet product line.

Siemens states the source advisory reports no confirmed active exploitation specifically against RUGGEDCOM APE1808 deployments; severity here is driven by the CVSS 9.8 ceiling and OT-device exposure, though CVE-2024-23113 is independently confirmed under active exploitation in the wild against Fortinet deployments generally per the CISA KEV listing. Siemens' primary remediation is upgrading the bundled Fortinet NGFW to V7.4.3 or later, or contacting Siemens customer support for patch guidance; per-CVE Fortinet workarounds (disabling FGFM interface access, disabling SSL-VPN web mode, disabling FortiAuthenticator push notifications, setting admin-host to prevent Host-header abuse) apply where the underlying FortiOS build cannot be immediately updated.

MITRE ATT&CK techniques used in TL-2026-2489

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1552 Unsecured Credentials

Reconnaissance

T1595 Active Scanning

Affected products and versions in Multiple Fortinet FortiOS Vulnerabilities (incl.

  • Siemens — RUGGEDCOM APE1808
    Vulnerable versions: All versions with bundled Fortinet NGFW earlier than V7.4.3
    Fixed in: Bundled Fortinet NGFW V7.4.3 or later
  • Fortinet — FortiOS
    Vulnerable versions: 7.0.0-7.0.13; 7.2.0-7.2.6; 7.4.0-7.4.2; 6.4.x and 6.2.x for select CLI format-string CVEs
    Fixed in: 7.0.14+; 7.2.7+; 7.4.3+ (per-CVE fixed builds vary; see individual FG-IR advisories)
  • Fortinet — FortiProxy
    Vulnerable versions: 7.0.0-7.0.14; 7.2.0-7.2.8; 7.4.0-7.4.2
    Fixed in: 7.0.15+; 7.2.9+; 7.4.3+
  • Fortinet — FortiPAM
    Vulnerable versions: 1.0.0-1.0.3; 1.1.0-1.1.2; 1.2.0
    Fixed in: 1.0.4+; 1.1.3+; 1.2.1+
  • Fortinet — FortiSwitchManager
    Vulnerable versions: 7.0.0-7.0.3; 7.2.0-7.2.3
    Fixed in: 7.0.4+; 7.2.4+

Remediation for Multiple Fortinet FortiOS Vulnerabilities (incl.

Patches

  • Update the RUGGEDCOM APE1808's bundled Fortinet NGFW to V7.4.3 or later per Siemens SSA-832273
  • Apply Fortinet FG-IR-24-029 fixed builds for CVE-2024-23113 (FortiOS 7.0.14+, 7.2.7+, 7.4.3+; FortiProxy 7.0.15+, 7.2.9+, 7.4.3+; FortiPAM 1.0.4+/1.1.3+/1.2.1+; FortiSwitchManager 7.0.4+/7.2.4+)
  • Apply the curl 8.4.0+ fix for CVE-2023-38545 where curl/libcurl is bundled independently of the FortiOS release train
  • Apply Fortinet FG-IR-23-315 fixed builds (FortiOS 7.2.6+/7.4.2+) for CVE-2023-44250
  • Apply Fortinet FG-IR-24-013 fixed builds for CVE-2024-23112 and FG-IR-24-032 fixed builds for CVE-2024-26011

Immediate actions

  • Restrict or disable exposure of the FGFM management service (default TCP/541) on every interface to close CVE-2024-23113's unauthenticated attack surface
  • Disable SSL-VPN web mode where CVE-2024-23112 (bookmark IDOR) and related SSL-VPN issues cannot yet be patched
  • Disable FortiAuthenticator push notifications as an interim mitigation for CVE-2023-46717
  • Set the admin-host property to the device hostname to prevent Host-header-based cache poisoning (CVE-2022-23439)
  • Restrict CLI/administrative access to trusted management networks only, since multiple format-string CVEs (CVE-2023-48784, CVE-2023-36640, CVE-2023-40721, CVE-2023-45583) require privileged CLI or HTTP(S) access to trigger

Workarounds

  • Disable FGFM access per interface (CVE-2024-23113 interim mitigation per Fortinet advisory)
  • Disable SSL-VPN web mode (CVE-2024-23112 interim mitigation)
  • Set admin-host to the device hostname to disable Host-header redirection (CVE-2022-23439 interim mitigation)
  • Contact Siemens customer support for interim patch guidance specific to the RUGGEDCOM APE1808 bundle

Longer-term hardening

  • Track Siemens ProductCERT revisions to SSA-832273 for the RUGGEDCOM APE1808 bundle image update carrying Fortinet NGFW V7.4.3+
  • Establish a patch-tracking process for embedded/bundled third-party firmware inside OT gateway hardware, since bundled components lag the upstream vendor's own patch cadence
  • Deploy network segmentation between RUGGEDCOM APE1808 management interfaces and untrusted networks to reduce exposure to unauthenticated exploitation paths
  • Monitor CISA KEV and Shadowserver internet-exposure reporting for CVE-2024-23113 given confirmed active exploitation against Fortinet deployments generally

CVEs associated with Multiple Fortinet FortiOS Vulnerabilities (incl.

  • CVE-2023-38545
  • CVE-2023-38546
  • CVE-2023-44250
  • CVE-2023-44487
  • CVE-2024-23113
  • CVE-2023-47537
  • CVE-2023-46717
  • CVE-2024-23112
  • CVE-2023-41677
  • CVE-2024-23662
  • CVE-2023-48784
  • CVE-2023-45586
  • CVE-2024-26007
  • CVE-2023-36640
  • CVE-2023-45583
  • CVE-2023-44247
  • CVE-2023-46714
  • CVE-2024-23110
  • CVE-2022-45862
  • CVE-2024-26011
  • CVE-2022-23439
  • CVE-2023-42785
  • CVE-2023-42786
  • CVE-2023-46715
  • CVE-2023-40721
  • CVE-2025-54822
  • CVE-2023-46718
  • CVE-2024-40593

Weaknesses (CWE) in Multiple Fortinet FortiOS Vulnerabilities (incl.

CWE-134, CWE-787, CWE-400, CWE-639, CWE-269, CWE-415, CWE-610, CWE-306

Timeline of Multiple Fortinet FortiOS Vulnerabilities (incl.

  • CVE-2023-44487 (HTTP/2 Rapid Reset) is publicly disclosed via coordinated vendor advisories after being exploited in the wild for record-scale DDoS since August 2023.
  • The curl project ships version 8.4.0, fixing the CVE-2023-38545 SOCKS5 proxy heap buffer overflow later inherited into this FortiOS advisory bundle.
  • Fortinet PSIRT publishes FG-IR-23-315 (CVE-2023-44250, HA cluster privilege escalation) and FG-IR-23-195 (CVE-2023-44247, double free in json_object_put).
  • Fortinet PSIRT publishes FG-IR-24-029 disclosing CVE-2024-23113, a critical unauthenticated format-string RCE in the fgfmd daemon (CVSS 9.8), alongside FG-IR-24-013 (CVE-2024-23112) and FG-IR-24-032 (CVE-2024-26011).
  • Siemens ProductCERT issues the initial SSA-832273 V1.0 advisory listing Fortinet FortiOS vulnerabilities affecting RUGGEDCOM APE1808 devices running bundled Fortinet NGFW below V7.4.3.
  • CISA adds CVE-2024-23113 to the Known Exploited Vulnerabilities catalog, confirming active exploitation and giving U.S. federal agencies a three-week remediation deadline.
  • The Shadowserver Foundation reports over 87,000 internet-facing Fortinet devices remain vulnerable to CVE-2024-23113 months after the patch became available.
  • Siemens updates SSA-832273 to revision V2.1, the current version tracked by this threat record, reflecting the accumulated bundle of 28 Fortinet CVEs.

Sources cited for Multiple Fortinet FortiOS Vulnerabilities (incl.

More in vulnerability

Detection coverage for TL-2026-2489

As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2489 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats