A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the
installation directory of the affected systems. The filename for
the target file can be specified, thus arbitrary files can be
overwritten by an attacker with the required privileges.
installation directory of the affected systems. The filename for
the target file can be specified, thus arbitrary files can be
overwritten by an attacker with the required privileges.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25120 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus arbitrary files can be overwritten by an attacker with the required privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Feb 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-02T00:41:55.909Z
Reserved: 2024-02-28T16:38:00.193Z
Link: CVE-2024-27946
Updated: 2024-05-14T13:10:51.858Z
Status : Analyzed
Published: 2024-05-14T16:16:33.783
Modified: 2025-02-06T18:14:26.713
Link: CVE-2024-27946
No data.
OpenCVE Enrichment
No data.
EUVD