First published: Tue May 14 2024(Updated: )
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens RUGGEDCOM CROSSBOW | <V5.5 | |
Siemens RUGGEDCOM CROSSBOW | <5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27945 is rated as a critical vulnerability due to the potential for privileged users to upload and tamper with files in the RUGGEDCOM CROSSBOW system.
To mitigate CVE-2024-27945, upgrade RUGGEDCOM CROSSBOW to version 5.5 or later.
CVE-2024-27945 affects all versions of RUGGEDCOM CROSSBOW that are prior to version 5.5.
An attacker can upload files to the root installation directory, potentially replacing critical files and compromising system integrity.
Currently, the best course of action for CVE-2024-27945 is to apply the available software update to version 5.5 or higher.