CVE-2023-27463: SQL Injection
Published Mar 14, 2023
·Updated
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
Affected Software
1 affected component
Siemens Ruggedcom Crossbow<5.3
Event History
Mar 14, 2023
CVE Published
via MITRE·09:32 AM
Data Sourced
via MITRE·09:32 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27463.
2
What is the title of the vulnerability?
The title of the vulnerability is "A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form …"
3
What is the affected software?
The affected software is Siemens Ruggedcom Crossbow (All versions < V5.3).
4
What is the severity of CVE-2023-27463?
The severity of CVE-2023-27463 is high with a severity value of 8.8.
5
What is the Common Weakness Enumeration (CWE) ID?
The Common Weakness Enumeration (CWE) ID for CVE-2023-27463 is CWE-89.