CVE-2023-27309: High severity siemens ruggedcom crossbow vulnerability
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27309?
CVE-2023-27309 is a vulnerability identified in RUGGEDCOM CROSSBOW (All versions < V5.2) that allows an authenticated remote attacker to perform unauthorized actions.
How severe is CVE-2023-27309?
CVE-2023-27309 has a severity rating of 8.8 (high).
What software versions are affected by CVE-2023-27309?
All versions of RUGGEDCOM CROSSBOW < V5.2 are affected by CVE-2023-27309.
How can an attacker exploit CVE-2023-27309?
An attacker can exploit CVE-2023-27309 by sending unauthorized write queries to the client query handler of the affected application.
Is there a fix for CVE-2023-27309?
Yes, upgrading to version 5.2 or above of RUGGEDCOM CROSSBOW will fix CVE-2023-27309.