PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40899 Siemens CVE debrief

CVE-2025-40899 is a high-severity stored cross-site scripting issue in the Assets and Nodes functionality. An authenticated user with custom fields privileges can place a malicious custom field that is later rendered in another user's browser, letting the attacker act in the victim's session and potentially modify data, disrupt availability, or view limited sensitive information. The supplied advisory was first published on 2026-01-13 and updated on 2026-05-14.

Vendor
Siemens
Product
RUGGEDCOM APE1808
CVSS
HIGH 8.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-13
Original CVE updated
2026-07-09
Advisory published
2026-01-13
Advisory updated
2026-07-09

Who should care

Siemens RUGGEDCOM APE1808 operators, OT/ICS administrators, security teams managing Assets and Nodes workflows, and anyone who can create or review custom fields in the affected environment.

Technical summary

The issue is a stored XSS condition caused by improper validation of an input parameter in the Assets and Nodes pages. Exploitation requires authentication and custom fields privileges, but once a payload is stored it executes in the browser context of a later viewer. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H, which reflects low attack complexity, required user interaction, and high integrity/availability impact. The corpus also maps the issue to CWE-79.

Defensive priority

High. Treat this as a priority patch and privilege-review item, especially where Assets and Nodes are used by administrators or operators. Stored XSS with browser-session impact can quickly become a data integrity and service availability problem in OT-facing management interfaces.

Recommended defensive actions

  • Upgrade to the vendor-fixed release referenced in the advisory: v26.2.0, and follow Siemens customer support guidance for patch and update details.
  • Verify the exact affected product and remediation path before change windows, because the supplied corpus ties the advisory to Siemens RUGGEDCOM APE1808 while the remediation field names Nozomi Guardian v26.2.0.
  • Restrict custom fields privileges to the smallest practical set of trusted users and review existing assignments.
  • Review Assets and Nodes content for suspicious custom field values and remove or sanitize any unexpected script-bearing entries.
  • Apply layered ICS/OT defensive practices such as least privilege, strong session controls, and defense-in-depth around management interfaces.
  • Monitor for unusual administrator actions or data changes that could indicate abuse of a stored XSS condition.

Evidence notes

Assessment is based on the CISA CSAF advisory ICSA-26-015-07, published 2026-01-13 and republished/updated through 2026-05-14, plus the linked Siemens ProductCERT advisory SSA-827968. The corpus explicitly describes an authenticated stored XSS in Assets and Nodes caused by improper input validation. The advisory metadata contains a product/remediation naming mismatch, so the exact fix path should be manually verified before remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40899 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40899

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40899 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40899

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-827968.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-827968.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.