CVE-2023-37372: SQL Injection
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37372?
CVE-2023-37372 is a vulnerability identified in RUGGEDCOM CROSSBOW, affecting all versions prior to V5.4. It is a SQL injection vulnerability that can be exploited by unauthenticated remote attackers to execute arbitrary SQL queries on the server database.
What is the severity of CVE-2023-37372?
The severity of CVE-2023-37372 is rated as critical, with a severity score of 9.8 out of 10.
How does CVE-2023-37372 affect Siemens Ruggedcom Crossbow?
CVE-2023-37372 affects all versions of Siemens Ruggedcom Crossbow prior to V5.4, making them vulnerable to SQL injection attacks.
How can an attacker exploit CVE-2023-37372?
An attacker can exploit CVE-2023-37372 by sending specially crafted SQL queries to the vulnerable server, allowing them to execute arbitrary SQL commands.
Is there a fix available for CVE-2023-37372?
Yes, the fix for CVE-2023-37372 is to update Ruggedcom Crossbow to version 5.4 or later.