PT-2024-5193 · Siemens · Ruggedcom Crossbow

Published

2024-05-14

·

Updated

2024-05-14

·

CVE-2024-27943

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: RUGGEDCOM CROSSBOW versions prior to V5.5
Description: The issue is related to incorrect external control of a file name or path in the Firmware Upload Handler component of the RUGGEDCOM CROSSBOW system. This could allow a remote attacker to upload arbitrary files and execute arbitrary code. A privileged user can upload generic files to the root installation directory, potentially allowing an attacker to tamper with specific files or achieve remote code execution.
Recommendations: For versions prior to V5.5, update to version V5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Firmware Upload Handler component to minimize the risk of exploitation. Additionally, restrict file uploads to authorized users and validate file types to prevent arbitrary file uploads.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05750
CVE-2024-27943

Affected Products

Ruggedcom Crossbow