A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-31086 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-02-27T15:00:08.924Z
Reserved: 2023-02-28T09:05:35.296Z
Link: CVE-2023-27309
Updated: 2024-08-02T12:09:43.454Z
Status : Modified
Published: 2023-03-14T10:15:28.677
Modified: 2024-11-21T07:52:37.310
Link: CVE-2023-27309
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD