CVE-2024-27939: Siemens Ruggedcom Crossbow

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.

Affected products

  • Siemens Ruggedcom Crossbow: before 5.5 (fixed in 5.5)

Published 2024-05-14. Last modified 2026-06-17.