PT-2023-4365 · Siemens · Ruggedcom Crossbow

Published

2023-08-08

·

Updated

2023-08-10

·

CVE-2023-37372

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RUGGEDCOM CROSSBOW versions prior to V5.4
Description The issue is related to a lack of protection against SQL query structure attacks, making the system vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.
Recommendations For versions prior to V5.4, update to version V5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the database server to minimize the risk of exploitation. Avoid using vulnerable SQL queries until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04710
CVE-2023-37372

Affected Products

Ruggedcom Crossbow