A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the
installation directory of the affected systems. The filename for
the target file can be specified, thus arbitrary files can be
overwritten by an attacker with the required privileges.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
https://cert-portal.siemens.com/productcert/html/ssa-916916.html | Vendor Advisory |
Configurations
History
06 Feb 2025, 18:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory | |
CPE | cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* | |
First Time |
Siemens ruggedcom Crossbow
Siemens |
Information
Published : 2024-05-14 16:16
Updated : 2025-02-06 18:14
NVD link : CVE-2024-27946
Mitre link : CVE-2024-27946
CVE.ORG link : CVE-2024-27946
JSON object : View
Products Affected
siemens
- ruggedcom_crossbow
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')