CVE-2024-27940

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-14 16:16

Updated : 2024-05-14 19:18


NVD link : CVE-2024-27940

Mitre link : CVE-2024-27940

CVE.ORG link : CVE-2024-27940


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')