First published: Tue Aug 08 2023(Updated: )
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Ruggedcom Crossbow | <5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-27411.
The severity of CVE-2023-27411 is high, with a severity value of 8.8.
The affected software is Siemens Ruggedcom Crossbow (All versions < V5.4).
The impact of CVE-2023-27411 is that an authenticated remote attacker can execute arbitrary SQL queries on the server database and escalate privileges.
Siemens has released a security advisory with mitigation and remediation steps. Please refer to the reference link for more information.