Full Report
Nozomi Networks has published information on vulnerabilities in Nozomi Guardian/CMC. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.
Analysis Summary
# Vulnerability: Multiple Flaws in Nozomi Guardian/CMC on Siemens RUGGEDCOM APE1808
## CVE Details
* **CVE ID:** CVE-2024-13089, CVE-2024-13090, CVE-2025-1501, CVE-2025-40888, CVE-2025-3718, CVE-2025-3719, CVE-2025-40885, CVE-2025-40886, CVE-2025-40887, CVE-2025-40889, CVE-2025-40890
* **CVSS Score:** 8.1 (High) - *Based on CVSS v3.1 for CVE-2025-40889* (CVSS v4.0: 7.7)
* **CWE:** CWE-22 (Path Traversal), CWE-79 (Stored XSS), and others.
## Affected Systems
* **Products:** RUGGEDCOM APE1808 (Application Hosting Platform)
* **Versions:** All versions running Nozomi Guardian/CMC before V25.4.0.
* **Configurations:** Performance of the upgrade via the Web GUI may exhibit errors; CLI is requested for updates.
## Vulnerability Description
This advisory covers multiple vulnerabilities identified in the Nozomi Guardian/CMC software integrated into Siemens RUGGEDCOM devices. Key technical flaws include:
* **Path Traversal (CVE-2025-40889):** Missing validation of input parameters in the Backup/Restore functionality allows an authenticated, low-privileged user to alter or delete files in the `/data` folder.
* **Stored XSS (CVE-2025-40890):** Improper validation in the Dashboards functionality allow attackers to inject malicious JavaScript. This payload executes when victim users view or import the dashboard.
* **Other Flaws:** The suite includes various vulnerabilities affecting management interfaces, requiring authenticated access but leading to potential integrity and availability compromises.
## Exploitation
* **Status:** Not reported as exploited in the wild; PoC status not explicitly detailed but technical vectors are documented.
* **Complexity:** Low to Medium (depending on the specific CVE and requirement for social engineering).
* **Attack Vector:** Network.
## Impact
* **Confidentiality:** Low to None (Limited sensitive information access via XSS).
* **Integrity:** High (Ability to modify application data and alter system files).
* **Availability:** High (Ability to disrupt application availability or delete critical data).
## Remediation
### Patches
* **Upgrade to Nozomi Guardian / CMC V25.4.0.**
* *Note:* Siemens recommends using the **CLI** for the upgrade process as the Web GUI may encounter errors. Contact Siemens customer support to obtain the patch.
### Workarounds
* **Access Control:** Use internal firewall features to restrict access to the web management interface to trusted IPs only.
* **Account Audit:** Review all authorized accounts and delete unnecessary or dormant credentials.
* **Session Security:** Avoid visiting external websites or clicking untrusted links while an authenticated session to the management interface is active.
* **Trusted Sources:** Only install update packages verified from trusted sources.
## Detection
* **Indicators of Compromise:** Unusual file modifications in the `/data` directory; unauthorized dashboard templates or modified dashboard configurations.
* **Detection Methods:** Audit web server logs for suspicious path traversal patterns (e.g., `../`) or script tags in dashboard-related API requests.
## References
* **Siemens Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/pdf/ssa-978177[.]pdf
* **Nozomi Networks Advisories:**
* hxxps://security[.]nozominetworks[.]com/NN-2025:1-01/
* hxxps://security[.]nozominetworks[.]com/NN-2025:3-01/
* **Operational Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security