Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27310

March 14, 2023, 10:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.

cve

Cyber Security Specialist

@ NielsenIQ | Algiers, Algeria

Chief Information Security Officer

@ Business Wire | United States

Sr. Red Team Engineer

@ Picus | Ankara, Turkey

Cyber Security Expert

@ AVIV Group | Paris, France

Security Architect

@ Eurofins | Barcelona, Poland

Engineering Manager, Cloud Security

@ Patreon | Remote

Sr. Cybersecurity Engineer - Identity and Access Management

@ Visa | Bengaluru, India

Research Engineer- Atmospheric Perils Vulnerability

@ Verisk | Boston, MA, United States

Security Engineer, SIRT

@ Amazon.com | Dublin, IRL

Sr Incident Response Analyst

@ ServiceNow | Dublin, Ireland

Security Architect

@ AVIV Group | Paris, France

Regulatory Compliance Specialist - ISMS

@ Intelerad | Remote, OR, United States