Brief

Summary:

The document provides a security advisory from Siemens regarding vulnerabilities in their RUGGEDCOM CROSSBOW product. The vulnerabilities, with a CVSS v3 score ranging from 5.3 to 9.8, allow for remote exploitation and can lead to arbitrary code execution, file uploads, and denial-of-service situations.

The affected products are versions prior to V5.5, and the vulnerabilities include missing authorization, improper neutralization of special elements, missing authentication, external control of file names or paths, improper limitation of pathnames, and exposure of sensitive information.

Siemens recommends updating the product to version V5.5 or later, as well as implementing general security measures such as network access control and firewalls. The United States Computer Emergency Readiness Team (US-CERT) also provides guidelines for minimizing the risk of exploitation, including minimizing network exposure, isolating control systems, and using more secure remote access methods.

1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Siemens Equipment: RUGGEDCOM CROSSBOW Vulnerabilities: Missing Authorization, Improper Neutralization of Special Elements used in an SQL Command, Missing Authentication for Critical Function, External Control of File Name or Path, Improper Limitation of a Pathname to a Restricted Directory, Exposure of Sensitive Information to

This content is restricted.

Highlights content goes here...

1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Siemens Equipment: RUGGEDCOM CROSSBOW Vulnerabilities: Missing Authorization, Improper Neutralization of Special Elements used in an SQL Command, Missing Authentication for Critical Function, External Control of File Name or Path, Improper Limitation of a Pathname to a Restricted Directory, Exposure of Sensitive Information to

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies