Lucene search

K
vulnrichmentSiemensVULNRICHMENT:CVE-2024-27939
HistoryMay 14, 2024 - 10:02 a.m.

CVE-2024-27939

2024-05-1410:02:07
CWE-862
siemens
github.com
vulnerability
ruggedcom crossbow
arbitrary file upload
unauthenticated user
arbitrary code execution
system privileges

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

7.7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "RUGGEDCOM CROSSBOW",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V5.5",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

7.7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for VULNRICHMENT:CVE-2024-27939