CVE-2023-37373
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Aug 8, 2023
Updated: Aug 10, 2023
CWE ID 306
Summary
CVE-2023-37373 is a newly disclosed vulnerability affecting RUGGEDCOM CROSSBOW versions prior to V5.4. This issue allows unauthenticated attackers to write arbitrary files to the application's file system by sending unauthenticated file write messages. The vulnerability poses a significant risk, as an attacker can potentially install malicious software or gain unauthorized access to sensitive data. It is recommended that users of the affected applications upgrade to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Siemens AG