PatchSiren cyber security CVE debrief
CVE-2022-2347 Siemens CVE debrief
CVE-2022-2347 is a pre-boot memory corruption issue in U-Boot’s USB DFU path. According to the supplied record, the DFU implementation does not bound the USB download setup packet length or verify that the transfer direction matches the command, allowing a physical attacker to exceed the heap-allocated request buffer when wLength is greater than 4096 bytes.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
U-Boot maintainers, embedded device vendors, OEM firmware teams, and security teams responsible for products that expose USB DFU or other pre-boot recovery interfaces where physical access is realistic.
Technical summary
The issue is an unchecked length field in U-Boot DFU download setup handling. The supplied NVD record says the vulnerable range covers denx:u-boot versions from 2012.10 through 2022.07 and maps the flaw to CWE-787 as primary, with CWE-122 also noted in the coordination reference. The CVSS vector is AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, reflecting that exploitation requires local/physical access and interaction, but can still have high impact on confidentiality, integrity, and availability.
Defensive priority
High. This is a memory corruption flaw in bootloader code exposed through USB DFU, so affected products should treat it as a firmware-security priority whenever physical access or service-mode access is plausible.
Recommended defensive actions
- Upgrade to a U-Boot release newer than 2022.07, or apply the vendor backport/fix if you maintain a downstream fork.
- Disable USB DFU on products that do not require it, especially in deployed devices with exposed physical ports.
- Restrict physical access to devices that keep DFU enabled, including service benches, kiosks, and field-deployed systems.
- Review downstream code for similar unchecked USB request lengths and ensure the transfer direction is validated against the command.
- Add regression tests for DFU request parsing, including length bounds and direction checks.
Evidence notes
The supplied NVD record states that U-Boot DFU does not bound the USB DFU download setup packet length and does not verify transfer direction, and that a physical attacker can overrun the heap-allocated request buffer when wLength exceeds 4096 bytes. NVD lists the vulnerable CPE range as denx:u-boot from 2012.10 through 2022.07 and assigns CVSS 3.1 vector AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. The record includes references to oss-sec, Debian LTS, and Siemens ProductCERT; the full text of those references is not included in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-2347 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-2347
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-2347 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-2347
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.