CVE-2026-27668
8.8Siemens · RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
A privilege escalation vulnerability in Siemens RUGGEDCOM CROSSBOW SAM-P allows authenticated user administrators to gain unauthorized access to any device group by modifying their own group permissions.
Executive summary
An authenticated privilege escalation vulnerability in Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) allows users to bypass authorization controls and gain unauthorized access to restricted device groups.
Vulnerability
The software suffers from incorrect privilege assignment (CWE-266), which permits an authenticated User Administrator to escalate their privileges by modifying the access levels of groups they currently belong to.
Business impact
This vulnerability poses a significant risk to operational security, as it allows internal users to exceed their authorized permissions and gain full control over any device group managed by the system. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to unauthorized configuration changes, data compromise, or disruption of critical infrastructure managed by the RUGGEDCOM platform.
Remediation
Immediate Action: Update Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) to version V5.8 or later to remediate the privilege assignment flaw.
Proactive Monitoring: Audit user account activities and group membership changes within the SAM-P interface to identify any unauthorized modifications or anomalous privilege escalations.
Compensating Controls: Implement strict identity and access management (IAM) policies to limit the number of users with administrative privileges, and ensure that all management interface access is restricted to authorized network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing Siemens RUGGEDCOM CROSSBOW SAM-P must prioritize upgrading to version V5.8 to address this privilege escalation risk. Failure to patch allows authenticated administrators to bypass standard security boundaries, potentially resulting in unauthorized control over connected industrial devices.