CVE-2024-27945

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*

History

06 Feb 2025, 18:14

Type Values Removed Values Added
First Time Siemens ruggedcom Crossbow
Siemens
CWE CWE-73 CWE-434
CPE cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

14 May 2024, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:16

Updated : 2025-02-06 18:14


NVD link : CVE-2024-27945

Mitre link : CVE-2024-27945


JSON object : View

Products Affected

siemens

  • ruggedcom_crossbow
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type