PatchSiren cyber security CVE debrief
CVE-2025-40899 Siemens CVE debrief
CVE-2025-40899 is a high-severity stored cross-site scripting issue in the Assets and Nodes functionality. An authenticated user with custom fields privileges can place a malicious custom field that is later rendered in another user's browser, letting the attacker act in the victim's session and potentially modify data, disrupt availability, or view limited sensitive information. The supplied advisory was first published on 2026-01-13 and updated on 2026-05-14.
- Vendor
- Siemens
- Product
- RUGGEDCOM APE1808
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-07-09
Who should care
Siemens RUGGEDCOM APE1808 operators, OT/ICS administrators, security teams managing Assets and Nodes workflows, and anyone who can create or review custom fields in the affected environment.
Technical summary
The issue is a stored XSS condition caused by improper validation of an input parameter in the Assets and Nodes pages. Exploitation requires authentication and custom fields privileges, but once a payload is stored it executes in the browser context of a later viewer. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H, which reflects low attack complexity, required user interaction, and high integrity/availability impact. The corpus also maps the issue to CWE-79.
Defensive priority
High. Treat this as a priority patch and privilege-review item, especially where Assets and Nodes are used by administrators or operators. Stored XSS with browser-session impact can quickly become a data integrity and service availability problem in OT-facing management interfaces.
Recommended defensive actions
- Upgrade to the vendor-fixed release referenced in the advisory: v26.2.0, and follow Siemens customer support guidance for patch and update details.
- Verify the exact affected product and remediation path before change windows, because the supplied corpus ties the advisory to Siemens RUGGEDCOM APE1808 while the remediation field names Nozomi Guardian v26.2.0.
- Restrict custom fields privileges to the smallest practical set of trusted users and review existing assignments.
- Review Assets and Nodes content for suspicious custom field values and remove or sanitize any unexpected script-bearing entries.
- Apply layered ICS/OT defensive practices such as least privilege, strong session controls, and defense-in-depth around management interfaces.
- Monitor for unusual administrator actions or data changes that could indicate abuse of a stored XSS condition.
Evidence notes
Assessment is based on the CISA CSAF advisory ICSA-26-015-07, published 2026-01-13 and republished/updated through 2026-05-14, plus the linked Siemens ProductCERT advisory SSA-827968. The corpus explicitly describes an authenticated stored XSS in Assets and Nodes caused by improper input validation. The advisory metadata contains a product/remediation naming mismatch, so the exact fix path should be manually verified before remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40899 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40899
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40899 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40899
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-827968.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-827968.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.