RUGGEDCOM CROSSBOW <5.5 Unauth Client Disconnects Users (DoS)
CVE-2024-27942 Published on May 14, 2024

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.

NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2024-27942

Want to know whenever a new CVE is published for Siemens Ruggedcom Crossbow? stack.watch will email you.

 

Affected Versions

Siemens RUGGEDCOM CROSSBOW: siemens ruggedcom_crossbow:

Exploit Probability

EPSS
0.43%
Percentile
62.01%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.