A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25114 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-02T00:41:55.962Z
Reserved: 2024-02-28T16:38:00.192Z
Link: CVE-2024-27940
Updated: 2024-05-14T13:13:47.139Z
Status : Analyzed
Published: 2024-05-14T16:16:24.733
Modified: 2025-02-06T18:16:23.880
Link: CVE-2024-27940
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD