CVE-2024-27945: Malicious File Upload
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27945?
CVE-2024-27945 is rated as a critical vulnerability due to the potential for privileged users to upload and tamper with files in the RUGGEDCOM CROSSBOW system.
How do I fix CVE-2024-27945?
To mitigate CVE-2024-27945, upgrade RUGGEDCOM CROSSBOW to version 5.5 or later.
Who is affected by CVE-2024-27945?
CVE-2024-27945 affects all versions of RUGGEDCOM CROSSBOW that are prior to version 5.5.
What can an attacker do with CVE-2024-27945?
An attacker can upload files to the root installation directory, potentially replacing critical files and compromising system integrity.
Is there a workaround for CVE-2024-27945?
Currently, the best course of action for CVE-2024-27945 is to apply the available software update to version 5.5 or higher.