CVE-2024-27944

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*

History

06 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-434
First Time Siemens ruggedcom Crossbow
Siemens
References () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory
CPE cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*

Information

Published : 2024-05-14 16:16

Updated : 2025-02-06 18:15


NVD link : CVE-2024-27944

Mitre link : CVE-2024-27944

CVE.ORG link : CVE-2024-27944


JSON object : View

Products Affected

siemens

  • ruggedcom_crossbow
CWE
CWE-73

External Control of File Name or Path

CWE-434

Unrestricted Upload of File with Dangerous Type