CVE-2024-27944: Malicious File Upload
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27944?
CVE-2024-27944 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-27944?
To address CVE-2024-27944, upgrade RUGGEDCOM CROSSBOW to version 5.5 or later.
What systems are affected by CVE-2024-27944?
CVE-2024-27944 affects all versions of RUGGEDCOM CROSSBOW prior to version 5.5.
What type of attacks can exploit CVE-2024-27944?
CVE-2024-27944 can be exploited to tamper with files or achieve remote code execution by uploading malicious firmware.
Who is the vendor of the software affected by CVE-2024-27944?
The vendor of the affected software is Siemens, specifically the RUGGEDCOM division.