CVE-2024-27940: Siemens Ruggedcom Crossbow

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.

Affected products

  • Siemens Ruggedcom Crossbow: before 5.5 (fixed in 5.5)

Published 2024-05-14. Last modified 2026-06-17.