CVE-2023-27310: High severity siemens ruggedcom crossbow vulnerability
Published Mar 14, 2023
·Updated
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.
Affected Software
1 affected component
Siemens Ruggedcom Crossbow<5.2
Event History
Mar 14, 2023
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-27310?
CVE-2023-27310 is a vulnerability identified in RUGGEDCOM CROSSBOW (All versions < V5.2).
2
How severe is CVE-2023-27310?
CVE-2023-27310 has a severity rating of 8.8 (high).
3
What is the affected software of CVE-2023-27310?
The affected software of CVE-2023-27310 is Siemens Ruggedcom Crossbow (All versions < V5.2).
4
What is the CWE of CVE-2023-27310?
The CWE of CVE-2023-27310 is 862.
5
How can I fix CVE-2023-27310?
To fix CVE-2023-27310, update your RUGGEDCOM CROSSBOW software to version 5.2 or higher.