CVE-2024-27943

CVSS v3 Score
7.2
High

Vulnerability Description

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.

CVSS:7.2(High)

An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system ...

CWE-732020
CVSS:7.2(High)

An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and wri...

CWE-732020
CVSS:7.2(High)

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

CWE-732023
CVSS:7.2(High)

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system....

CWE-732024
CVSS:7.2(High)

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation direct...

CWE-732024
CVSS:7.2(High)

Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.04.5, a user with administrative privileges can upload files that look like imag...

CWE-732024