A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
Configurations
History
06 Feb 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| First Time |
Siemens ruggedcom Crossbow
Siemens |
|
| References | () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory | |
| CWE | CWE-434 |
14 May 2024, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-05-14 16:16
Updated : 2025-02-06 18:15
NVD link : CVE-2024-27943
Mitre link : CVE-2024-27943
JSON object : View
Products Affected
siemens
- ruggedcom_crossbow
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
