CVE-2023-27411: SQL Injection
Published Aug 8, 2023
·Updated
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges.
Affected Software
1 affected component
Siemens Ruggedcom Crossbow<5.4
Event History
Aug 8, 2023
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27411.
2
What is the severity of CVE-2023-27411?
The severity of CVE-2023-27411 is high, with a severity value of 8.8.
3
What is the affected software?
The affected software is Siemens Ruggedcom Crossbow (All versions < V5.4).
4
What is the impact of CVE-2023-27411?
The impact of CVE-2023-27411 is that an authenticated remote attacker can execute arbitrary SQL queries on the server database and escalate privileges.
5
Are there any known fixes for CVE-2023-27411?
Siemens has released a security advisory with mitigation and remediation steps. Please refer to the reference link for more information.