PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-27941 Siemens CVE debrief

A SQL injection vulnerability in Siemens RUGGEDCOM CROSSBOW client systems allows authenticated attackers to compromise the entire database due to improper input sanitization. The vulnerability, published 2024-05-14, carries a CVSS 3.1 score of 8.8 (HIGH) with network attack vector, low attack complexity, and low privileges required. Siemens has released version 5.5 as a remediation. CISA published advisory ICSA-24-137-10 coordinating with Siemens' security advisory SSA-916916. No known exploitation in ransomware campaigns has been documented.

Vendor
Siemens
Product
RUGGEDCOM CROSSBOW
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-14
Original CVE updated
2024-05-14
Advisory published
2024-05-14
Advisory updated
2024-05-14

Who should care

Organizations operating Siemens RUGGEDCOM CROSSBOW in industrial control system environments, critical infrastructure operators, database administrators managing backend systems for OT networks, and security teams responsible for ICS/SCADA security posture.

Technical summary

The vulnerability exists in client systems that fail to sanitize input data before transmitting to SQL servers. An attacker with low privileges can exploit this via network access to execute arbitrary SQL commands, resulting in complete database compromise with high impact to confidentiality, integrity, and availability. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates network exploitable, low complexity, low privilege requirements, and high impacts across all three security dimensions. Remediation requires updating to version 5.5 or later.

Defensive priority

HIGH

Recommended defensive actions

  • Apply vendor fix: Update Siemens RUGGEDCOM CROSSBOW to version 5.5 or later
  • Review database access logs for anomalous query patterns from client systems
  • Implement input validation and parameterized queries for all database interactions
  • Apply principle of least privilege to database accounts used by RUGGEDCOM CROSSBOW clients
  • Monitor CISA ICS advisories for additional guidance on industrial control system security

Evidence notes

CVE description and CVSS vector from CISA CSAF source ICSA-24-137-10. Vendor fix confirmed in CSAF remediations section with specific version guidance. No KEV listing present.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-27941 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-27941

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-27941 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-27941

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-137-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-916916.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-916916.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-916916.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-916916.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-137-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.