CVE-2024-27947
- EPSS 0.41%
- Published 14.05.2024 16:16:35
- Last modified 06.02.2025 18:13:55
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward ...
CVE-2024-27946
- EPSS 0.35%
- Published 14.05.2024 16:16:33
- Last modified 06.02.2025 18:14:26
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus ...
CVE-2024-27945
- EPSS 2.41%
- Published 14.05.2024 16:16:32
- Last modified 06.02.2025 18:14:57
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an...
CVE-2024-27944
- EPSS 2.41%
- Published 14.05.2024 16:16:31
- Last modified 06.02.2025 18:15:10
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could ta...
CVE-2024-27943
- EPSS 2.61%
- Published 14.05.2024 16:16:28
- Last modified 06.02.2025 18:15:25
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tam...
CVE-2024-27942
- EPSS 0.43%
- Published 14.05.2024 16:16:27
- Last modified 06.02.2025 18:15:39
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perf...
CVE-2024-27941
- EPSS 1.75%
- Published 14.05.2024 16:16:26
- Last modified 06.02.2025 18:16:12
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole dat...
CVE-2024-27940
- EPSS 1.3%
- Published 14.05.2024 16:16:24
- Last modified 06.02.2025 18:16:23
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole data...
CVE-2024-27939
- EPSS 1.04%
- Published 14.05.2024 16:16:23
- Last modified 06.02.2025 18:16:36
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution ...
CVE-2023-37372
- EPSS 0.68%
- Published 08.08.2023 10:15:15
- Last modified 21.11.2024 08:11:36
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.