CVE-2024-27940

Publication date

2024-05-14 10:02:08

Family

siemens

State

PUBLISHED

Description

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.