Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)
Multiple Fortinet FortiOS Vulnerabilities (incl. (TL-2026-2489), also tracked as SSA-832273, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-13. It has no confirmed attribution, affects Siemens RUGGEDCOM APE1808, references 28 CVEs (CVE-2023-38545, CVE-2023-38546, CVE-2023-44250), maps to 5 MITRE ATT&CK techniques (T1046, T1059, T1190), and is covered by 9 detection rules and 5 indicators of compromise.
Key facts for TL-2026-2489
- Threat ID
- TL-2026-2489
- Also known as
- SSA-832273
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-13
- Last reviewed
- 2026-09-13
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- industrial control systems, critical infrastructure, energy, utilities, transport, manufacturing, government administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 5
Siemens ProductCERT advisory SSA-832273 (rev V2.1, 2026-01-13) lists 28 Fortinet FortiOS/FortiProxy/FortiPAM/FortiSwitchManager CVEs affecting RUGGEDCOM APE1808 OT devices that bundle Fortinet NGFW below V7.4.3. The most severe, CVE-2024-23113, is an unauthenticated remote format-string RCE in the fgfmd daemon (CVSS 9.8) that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-09; the bundle also includes the curl SOCKS5 heap overflow (CVE-2023-38545) and the HTTP/2 Rapid Reset DoS (CVE-2023-44487).
How Multiple Fortinet FortiOS Vulnerabilities (incl. works
SSA-832273 is a Siemens ProductCERT advisory tracking third-party component risk: RUGGEDCOM APE1808 is a Siemens ruggedized application-processing-engine module deployed inside substation, rail, and utility RTU/gateway hardware, and it ships a bundled Fortinet NGFW (FortiOS-based) image below V7.4.3 that inherits 28 upstream Fortinet/curl CVEs. Because the NGFW is an embedded, bundled component rather than a standalone appliance the customer directly patches, the exposure persists on OT devices until Siemens ships (or the operator applies) an updated bundle image, independent of Fortinet's own patch cadence.
The most severe issue, CVE-2024-23113 (CVSS 9.8, CWE-134), is a use of externally-controlled format string in the fgfmd daemon that implements the FortiGate-to-FortiManager (FGFM) management protocol: a remote, unauthenticated attacker reaching the exposed FGFM service can send a crafted packet whose payload is passed unsanitized into a printf-style formatting function, yielding arbitrary code execution. Fortinet disclosed it via FG-IR-24-029; CISA added it to the KEV catalog on 2024-10-09 confirming active exploitation and mandating a three-week remediation window for federal agencies. As of 2024-10-15, Shadowserver reported 87,000+ internet-facing Fortinet devices were still vulnerable.
A second independently critical component is CVE-2023-38545 (CVSS 9.8, CWE-787), a heap buffer overflow in curl's SOCKS5 proxy handshake: when a target hostname exceeds 255 bytes during a slow handshake, an internal name-resolution-mode variable can be mis-set, causing curl to copy the oversized hostname into a fixed-size heap buffer meant for a resolved address. Because FortiOS bundles curl/libcurl, this upstream flaw (patched in curl 8.4.0) is inherited transitively; curl's own advisory lists SSA-832273 among the affected downstream products.
The bundle further includes CVE-2023-44487 (HTTP/2 Rapid Reset, CVSS 7.5), which enabled record-scale DDoS floods against HTTP/2 services worldwide in August-October 2023 by rapidly opening and RST-cancelling streams to exhaust server-side request-processing resources; a cluster of FortiOS/FortiProxy/FortiPAM/FortiSwitchManager CLI format-string bugs (CVE-2023-48784, CVE-2023-36640, CVE-2023-40721, CVE-2023-45583) that let a privileged CLI operator escalate to arbitrary code execution; an SSL-VPN bookmark IDOR (CVE-2024-23112, FG-IR-24-013, CWE-639) letting an authenticated user view another user's stored SSL-VPN bookmarks; an HA-cluster privilege-management flaw (CVE-2023-44250, FG-IR-23-315, CVSS 8.3) and a FortiAuthenticator-HA authentication flaw (CVE-2023-46717, CVSS 8.8) that let a read-only operator escalate to read-write; a missing-authentication flaw affecting the wider Fortinet product family (CVE-2024-26011, FG-IR-24-032, CVSS 9.8); a double-free in JSON object handling (CVE-2023-44247, FG-IR-23-195, CWE-415) reachable via crafted HTTP/HTTPS requests; and a web-cache-poisoning flaw via attacker-controlled Host headers (CVE-2022-23439, CWE-610) across the Fortinet product line.
Siemens states the source advisory reports no confirmed active exploitation specifically against RUGGEDCOM APE1808 deployments; severity here is driven by the CVSS 9.8 ceiling and OT-device exposure, though CVE-2024-23113 is independently confirmed under active exploitation in the wild against Fortinet deployments generally per the CISA KEV listing. Siemens' primary remediation is upgrading the bundled Fortinet NGFW to V7.4.3 or later, or contacting Siemens customer support for patch guidance; per-CVE Fortinet workarounds (disabling FGFM interface access, disabling SSL-VPN web mode, disabling FortiAuthenticator push notifications, setting admin-host to prevent Host-header abuse) apply where the underlying FortiOS build cannot be immediately updated.
MITRE ATT&CK techniques used in TL-2026-2489
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
Reconnaissance
Affected products and versions in Multiple Fortinet FortiOS Vulnerabilities (incl.
- Siemens — RUGGEDCOM APE1808
Vulnerable versions: All versions with bundled Fortinet NGFW earlier than V7.4.3
Fixed in: Bundled Fortinet NGFW V7.4.3 or later - Fortinet — FortiOS
Vulnerable versions: 7.0.0-7.0.13; 7.2.0-7.2.6; 7.4.0-7.4.2; 6.4.x and 6.2.x for select CLI format-string CVEs
Fixed in: 7.0.14+; 7.2.7+; 7.4.3+ (per-CVE fixed builds vary; see individual FG-IR advisories) - Fortinet — FortiProxy
Vulnerable versions: 7.0.0-7.0.14; 7.2.0-7.2.8; 7.4.0-7.4.2
Fixed in: 7.0.15+; 7.2.9+; 7.4.3+ - Fortinet — FortiPAM
Vulnerable versions: 1.0.0-1.0.3; 1.1.0-1.1.2; 1.2.0
Fixed in: 1.0.4+; 1.1.3+; 1.2.1+ - Fortinet — FortiSwitchManager
Vulnerable versions: 7.0.0-7.0.3; 7.2.0-7.2.3
Fixed in: 7.0.4+; 7.2.4+
Remediation for Multiple Fortinet FortiOS Vulnerabilities (incl.
Patches
- Update the RUGGEDCOM APE1808's bundled Fortinet NGFW to V7.4.3 or later per Siemens SSA-832273
- Apply Fortinet FG-IR-24-029 fixed builds for CVE-2024-23113 (FortiOS 7.0.14+, 7.2.7+, 7.4.3+; FortiProxy 7.0.15+, 7.2.9+, 7.4.3+; FortiPAM 1.0.4+/1.1.3+/1.2.1+; FortiSwitchManager 7.0.4+/7.2.4+)
- Apply the curl 8.4.0+ fix for CVE-2023-38545 where curl/libcurl is bundled independently of the FortiOS release train
- Apply Fortinet FG-IR-23-315 fixed builds (FortiOS 7.2.6+/7.4.2+) for CVE-2023-44250
- Apply Fortinet FG-IR-24-013 fixed builds for CVE-2024-23112 and FG-IR-24-032 fixed builds for CVE-2024-26011
Immediate actions
- Restrict or disable exposure of the FGFM management service (default TCP/541) on every interface to close CVE-2024-23113's unauthenticated attack surface
- Disable SSL-VPN web mode where CVE-2024-23112 (bookmark IDOR) and related SSL-VPN issues cannot yet be patched
- Disable FortiAuthenticator push notifications as an interim mitigation for CVE-2023-46717
- Set the admin-host property to the device hostname to prevent Host-header-based cache poisoning (CVE-2022-23439)
- Restrict CLI/administrative access to trusted management networks only, since multiple format-string CVEs (CVE-2023-48784, CVE-2023-36640, CVE-2023-40721, CVE-2023-45583) require privileged CLI or HTTP(S) access to trigger
Workarounds
- Disable FGFM access per interface (CVE-2024-23113 interim mitigation per Fortinet advisory)
- Disable SSL-VPN web mode (CVE-2024-23112 interim mitigation)
- Set admin-host to the device hostname to disable Host-header redirection (CVE-2022-23439 interim mitigation)
- Contact Siemens customer support for interim patch guidance specific to the RUGGEDCOM APE1808 bundle
Longer-term hardening
- Track Siemens ProductCERT revisions to SSA-832273 for the RUGGEDCOM APE1808 bundle image update carrying Fortinet NGFW V7.4.3+
- Establish a patch-tracking process for embedded/bundled third-party firmware inside OT gateway hardware, since bundled components lag the upstream vendor's own patch cadence
- Deploy network segmentation between RUGGEDCOM APE1808 management interfaces and untrusted networks to reduce exposure to unauthenticated exploitation paths
- Monitor CISA KEV and Shadowserver internet-exposure reporting for CVE-2024-23113 given confirmed active exploitation against Fortinet deployments generally
CVEs associated with Multiple Fortinet FortiOS Vulnerabilities (incl.
- CVE-2023-38545
CVE-2023-38546CVE-2023-44250- CVE-2023-44487
CVE-2024-23113CVE-2023-47537CVE-2023-46717CVE-2024-23112CVE-2023-41677CVE-2024-23662CVE-2023-48784CVE-2023-45586CVE-2024-26007CVE-2023-36640CVE-2023-45583CVE-2023-44247CVE-2023-46714CVE-2024-23110CVE-2022-45862CVE-2024-26011CVE-2022-23439CVE-2023-42785CVE-2023-42786CVE-2023-46715CVE-2023-40721CVE-2025-54822CVE-2023-46718CVE-2024-40593
Weaknesses (CWE) in Multiple Fortinet FortiOS Vulnerabilities (incl.
CWE-134, CWE-787, CWE-400, CWE-639, CWE-269, CWE-415, CWE-610, CWE-306
Timeline of Multiple Fortinet FortiOS Vulnerabilities (incl.
- CVE-2023-44487 (HTTP/2 Rapid Reset) is publicly disclosed via coordinated vendor advisories after being exploited in the wild for record-scale DDoS since August 2023.
- The curl project ships version 8.4.0, fixing the CVE-2023-38545 SOCKS5 proxy heap buffer overflow later inherited into this FortiOS advisory bundle.
- Fortinet PSIRT publishes FG-IR-23-315 (CVE-2023-44250, HA cluster privilege escalation) and FG-IR-23-195 (CVE-2023-44247, double free in json_object_put).
- Fortinet PSIRT publishes FG-IR-24-029 disclosing CVE-2024-23113, a critical unauthenticated format-string RCE in the fgfmd daemon (CVSS 9.8), alongside FG-IR-24-013 (CVE-2024-23112) and FG-IR-24-032 (CVE-2024-26011).
- Siemens ProductCERT issues the initial SSA-832273 V1.0 advisory listing Fortinet FortiOS vulnerabilities affecting RUGGEDCOM APE1808 devices running bundled Fortinet NGFW below V7.4.3.
- CISA adds CVE-2024-23113 to the Known Exploited Vulnerabilities catalog, confirming active exploitation and giving U.S. federal agencies a three-week remediation deadline.
- The Shadowserver Foundation reports over 87,000 internet-facing Fortinet devices remain vulnerable to CVE-2024-23113 months after the patch became available.
- Siemens updates SSA-832273 to revision V2.1, the current version tracked by this threat record, reflecting the accumulated bundle of 28 Fortinet CVEs.
Sources cited for Multiple Fortinet FortiOS Vulnerabilities (incl.
- Siemens Security Advisory SSA-832273 (V2.1): Multiple Vulnerabilities in Fortinet NGFW Before V7.4.3 on RUGGEDCOM APE1808 Devices
- FG-IR-24-029: FortiOS - Format string bug in fgfmd
- CISA Known Exploited Vulnerabilities Catalog - CVE-2024-23113
- CVE-2023-38545 - curl SOCKS5 heap buffer overflow
- Technical Breakdown: HTTP/2 Rapid Reset DDoS Attack
- 87,000+ Fortinet devices still open to attack, are yours among them? (CVE-2024-23113)
- FG-IR-24-013: Authorization bypass in SSLVPN bookmarks
- FG-IR-23-315: FortiOS - Privilege escalation in FortiGate HA cluster
- CVE-2023-44247 - Double free with double usage of json_object_put (FG-IR-23-195)
- NVD Detail - CVE-2024-23113
- Organizations Warned of Exploited Fortinet FortiOS Vulnerability
- FG-IR-24-032: Missing authentication for FGFM access control
More in vulnerability
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)
Detection coverage for TL-2026-2489
As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2489 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.