Known vulnerabilities in RUGGEDCOM CROSSBOW

Vendor: Siemens
Software CPE: cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:*
Total vulnerabilities: 18
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting RUGGEDCOM CROSSBOW RUGGEDCOM CROSSBOW is affected by 18 known vulnerabilities: 2 high, 8 medium, 8 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU89635 - Exposure of sensitive information to an unauthorized actor
CVE-2024-27947
CWE-200 Medium
No
No
5.5 17.05.2024 SB2024051720
#VU89632 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-27946
CWE-22 Low
No
No
5.5 17.05.2024 SB2024051720
#VU89629 - External Control of File Name or Path
CVE-2024-27945
CWE-73 Low
No
No
5.5 17.05.2024 SB2024051720
#VU89625 - External Control of File Name or Path
CVE-2024-27944
CWE-73 Low
No
No
5.5 17.05.2024 SB2024051720
#VU89621 - External Control of File Name or Path
CVE-2024-27943
CWE-73 Low
No
No
5.5 17.05.2024 SB2024051720
#VU89620 - Missing Authentication for Critical Function
CVE-2024-27942
CWE-306 Medium
No
No
5.5 17.05.2024 SB2024051720
#VU89619 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-27941
CWE-89 Medium
No
No
5.5 17.05.2024 SB2024051720
#VU89617 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-27940
CWE-89 Medium
No
No
5.5 17.05.2024 SB2024051720
#VU89614 - Missing Authorization
CVE-2024-27939
CWE-862 High
No
No
5.5 17.05.2024 SB2024051720
#VU79338 - Missing Authentication for Critical Function
CVE-2023-37373
CWE-306 Medium
No
No
5.4 10.08.2023 SB2023081011
#VU79333 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-37372
CWE-89 High
No
No
5.4 10.08.2023 SB2023081011
#VU79331 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-27411
CWE-89 Medium
No
No
5.4 10.08.2023 SB2023081011
#VU77807 - Out-of-bounds read
CVE-2021-31239
CWE-125 Low
No
No
5.4 29.06.2023 SB2023062933
SB2023081011
SB20230820151
and 6 more
#VU73706 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-27463
CWE-89 Medium
No
No
5.3 15.03.2023 SB2023031515
#VU73705 - Missing Authorization
CVE-2023-27462
CWE-862 Low
No
No
5.3 15.03.2023 SB2023031515
#VU73704 - Missing Authorization
CVE-2023-27310
CWE-862 Low
No
No
5.2 15.03.2023 SB2023031514
#VU73702 - Missing Authorization
CVE-2023-27309
CWE-862 Medium
No
No
5.2 15.03.2023 SB2023031514
#VU68139 - Absolute Path Traversal
CVE-2022-37971
CWE-36 Low
Available
No
5.4 11.10.2022 SB2022101147
SB2023081011