Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-27947
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client.
0
Attacker Value
Unknown
CVE-2024-27946
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the
installation directory of the affected systems. The filename for
the target file can be specified, thus arbitrary files can be
overwritten by an attacker with the required privileges.
0
Attacker Value
Unknown
CVE-2024-27945
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-27944
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-27943
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-27942
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.
0
Attacker Value
Unknown
CVE-2024-27941
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database.
0
Attacker Value
Unknown
CVE-2024-27940
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.
0
Attacker Value
Unknown
CVE-2024-27939
Disclosure Date: May 14, 2024 (last updated February 07, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.
0
Attacker Value
Unknown
CVE-2023-37373
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages. An unauthenticated remote attacker could write arbitrary files to the affected application's file system.
0