cvedb.io
CVE-2023-27310
MEDIUM · CVSS 6.6
EPSS exploitation probability: 0%
Published 2023-03-14T10:15:28.777 · Last modified 2026-06-17T05:44:45.637

Summary

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.

Affected products

siemens — ruggedcom_crossbow

Does this affect you?

Add your gear to cvedb and we'll alert you only when siemens ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.