A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
Configurations
History
06 Feb 2025, 18:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* | |
First Time |
Siemens ruggedcom Crossbow
Siemens |
|
CWE | CWE-434 | |
References | () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory |
Information
Published : 2024-05-14 16:16
Updated : 2025-02-06 18:14
NVD link : CVE-2024-27945
Mitre link : CVE-2024-27945
CVE.ORG link : CVE-2024-27945
JSON object : View
Products Affected
siemens
- ruggedcom_crossbow