PT-2024-5193 · Siemens · Ruggedcom Crossbow
Published
2024-05-14
·
Updated
2024-05-14
·
CVE-2024-27943
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
RUGGEDCOM CROSSBOW versions prior to V5.5
Description:
The issue is related to incorrect external control of a file name or path in the Firmware Upload Handler component of the RUGGEDCOM CROSSBOW system. This could allow a remote attacker to upload arbitrary files and execute arbitrary code. A privileged user can upload generic files to the root installation directory, potentially allowing an attacker to tamper with specific files or achieve remote code execution.
Recommendations:
For versions prior to V5.5, update to version V5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Firmware Upload Handler component to minimize the risk of exploitation. Additionally, restrict file uploads to authorized users and validate file types to prevent arbitrary file uploads.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruggedcom Crossbow