Siemens Ruggedcom Crossbow vulnerabilities
16 known vulnerabilities affecting siemens/ruggedcom_crossbow.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH11MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-27939CRITICALCVSS 9.8fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27939 [CRITICAL] CWE-862 CVE-2024-27939: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.
cvelistv5nvd
CVE-2024-27941HIGHCVSS 8.8fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27941 [HIGH] CWE-89 CVE-2024-27941: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database.
cvelistv5nvd
CVE-2024-27940HIGHCVSS 8.8fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27940 [HIGH] CWE-89 CVE-2024-27940: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.
cvelistv5nvd
CVE-2024-27943HIGHCVSS 7.2fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27943 [HIGH] CWE-73 CVE-2024-27943: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
cvelistv5nvd
CVE-2024-27944HIGHCVSS 7.2fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27944 [HIGH] CWE-73 CVE-2024-27944: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
cvelistv5nvd
CVE-2024-27945HIGHCVSS 7.2fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27945 [HIGH] CWE-73 CVE-2024-27945: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import fea
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
cvelistv5nvd
CVE-2024-27942HIGHCVSS 7.5fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27942 [HIGH] CWE-306 CVE-2024-27942: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.
cvelistv5nvd
CVE-2024-27947MEDIUMCVSS 5.3fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27947 [MEDIUM] CWE-200 CVE-2024-27947: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected system
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client.
cvelistv5nvd
CVE-2024-27946MEDIUMCVSS 6.5fixed in 5.5fixed in V5.52024-05-14
CVE-2024-27946 [MEDIUM] CWE-22 CVE-2024-27946: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files o
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the
installation directory of the affected systems. The filename for
the target file can be specified, thus arbitrary files can be
overwritten by an attacker with the required privileges.
cvelistv5nvd
CVE-2023-37372CRITICALCVSS 9.8fixed in 5.4vAll versions < V5.42023-08-08
CVE-2023-37372 [CRITICAL] CWE-89 CVE-2023-37372: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applic
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.
cvelistv5nvd
CVE-2023-27411HIGHCVSS 8.8fixed in 5.4vAll versions < V5.42023-08-08
CVE-2023-27411 [HIGH] CWE-89 CVE-2023-27411: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applic
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges.
cvelistv5nvd
CVE-2023-37373HIGHCVSS 7.5fixed in 5.4vAll versions < V5.42023-08-08
CVE-2023-37373 [MEDIUM] CWE-306 CVE-2023-37373: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applic
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages. An unauthenticated remote attacker could write arbitrary files to the affected application's file system.
cvelistv5nvd
CVE-2023-27309HIGHCVSS 8.8fixed in 5.2vAll versions < V5.22023-03-14
CVE-2023-27309 [MEDIUM] CWE-862 CVE-2023-27309: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query ha
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.
cvelistv5nvd
CVE-2023-27463HIGHCVSS 8.8fixed in 5.3vAll versions < V5.32023-03-14
CVE-2023-27463 [HIGH] CWE-89 CVE-2023-27463: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
cvelistv5nvd
CVE-2023-27310HIGHCVSS 8.8fixed in 5.2vAll versions < V5.22023-03-14
CVE-2023-27310 [MEDIUM] CWE-862 CVE-2023-27310: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query ha
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.
cvelistv5nvd
CVE-2023-27462MEDIUMCVSS 4.3fixed in 5.3vAll versions < V5.32023-03-14
CVE-2023-27462 [LOW] CWE-862 CVE-2023-27462: A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query ha
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for.
cvelistv5nvd