CVE-2023-27310
CVE-2023-27310
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.6EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected products
Siemens · RUGGEDCOM CROSSBOWWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →