CVE-2024-27940

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*

History

06 Feb 2025, 18:16

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - Vendor Advisory
CPE cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*
First Time Siemens ruggedcom Crossbow
Siemens

21 Nov 2024, 09:05

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-916916.html - () https://cert-portal.siemens.com/productcert/html/ssa-916916.html -
Summary
  • (es) Se ha identificado una vulnerabilidad en RUGGEDCOM CROSSBOW (Todas las versiones &lt; V5.5). Los sistemas afectados permiten que cualquier usuario autenticado envíe comandos SQL arbitrarios al servidor SQL. Un atacante podría utilizar esta vulnerabilidad para comprometer toda la base de datos.

14 May 2024, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:16

Updated : 2025-02-06 18:16


NVD link : CVE-2024-27940

Mitre link : CVE-2024-27940

CVE.ORG link : CVE-2024-27940


JSON object : View

Products Affected

siemens

  • ruggedcom_crossbow
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')