PatchSiren cyber security CVE debrief
CVE-2022-22128 Siemens CVE debrief
CVE-2022-22128 is a critical Siemens Opcenter Intelligence issue involving path traversal in an internal file transfer service. According to the advisory metadata, successful exploitation could allow remote code execution. The CVSS vector indicates network reachability with no privileges or user interaction required, and high impact to confidentiality, integrity, and availability. Siemens advises updating to V2501 or later and installing the latest available version as described in the vendor guidance.
- Vendor
- Siemens
- Product
- Opcenter Intelligence
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-02-11
- Advisory updated
- 2025-05-06
Who should care
Siemens Opcenter Intelligence administrators, OT/industrial control system operators, vulnerability management teams, and security responders responsible for network-exposed or enterprise-managed Siemens deployments.
Technical summary
The CISA CSAF advisory identifies a path traversal vulnerability in Siemens Opcenter Intelligence. The affected component is the product’s internal file transfer service. The provided CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H, which supports a high-severity assessment with potential remote code execution impact if successfully exploited. The advisory’s remediation points to Siemens version V2501 or later.
Defensive priority
High priority. This is a critical, network-reachable vulnerability with no privileges or user interaction required per the supplied CVSS vector, and the stated impact includes potential remote code execution.
Recommended defensive actions
- Update Siemens Opcenter Intelligence to V2501 or later, following the vendor guidance referenced in the Siemens advisory.
- Inventory all Opcenter Intelligence deployments and confirm which systems are affected.
- Limit access to the internal file transfer service to trusted hosts and segment industrial environments where possible.
- Review exposure of any network-facing or cross-zone pathways that could reach the affected service.
- Track the Siemens advisory and apply the latest available vendor-recommended version as soon as change control allows.
Evidence notes
This debrief follows the advisory metadata in the supplied CISA CSAF source for Siemens Opcenter Intelligence. The source corpus contains an internal description text that references Tableau Server Administration Agent, which conflicts with the advisory title, vendor, affected product, and remediation data identifying Siemens Opcenter Intelligence. For that reason, the debrief relies on the product and remediation metadata rather than the mismatched description text. The advisory was published on 2025-02-11 and revised on 2025-05-06 for typo fixes.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-22128 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-22128
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-22128 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-22128
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-14.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-246355.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-246355.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-14
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.