PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-2347 Siemens CVE debrief

CVE-2022-2347 is a pre-boot memory corruption issue in U-Boot’s USB DFU path. According to the supplied record, the DFU implementation does not bound the USB download setup packet length or verify that the transfer direction matches the command, allowing a physical attacker to exceed the heap-allocated request buffer when wLength is greater than 4096 bytes.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

U-Boot maintainers, embedded device vendors, OEM firmware teams, and security teams responsible for products that expose USB DFU or other pre-boot recovery interfaces where physical access is realistic.

Technical summary

The issue is an unchecked length field in U-Boot DFU download setup handling. The supplied NVD record says the vulnerable range covers denx:u-boot versions from 2012.10 through 2022.07 and maps the flaw to CWE-787 as primary, with CWE-122 also noted in the coordination reference. The CVSS vector is AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, reflecting that exploitation requires local/physical access and interaction, but can still have high impact on confidentiality, integrity, and availability.

Defensive priority

High. This is a memory corruption flaw in bootloader code exposed through USB DFU, so affected products should treat it as a firmware-security priority whenever physical access or service-mode access is plausible.

Recommended defensive actions

  • Upgrade to a U-Boot release newer than 2022.07, or apply the vendor backport/fix if you maintain a downstream fork.
  • Disable USB DFU on products that do not require it, especially in deployed devices with exposed physical ports.
  • Restrict physical access to devices that keep DFU enabled, including service benches, kiosks, and field-deployed systems.
  • Review downstream code for similar unchecked USB request lengths and ensure the transfer direction is validated against the command.
  • Add regression tests for DFU request parsing, including length bounds and direction checks.

Evidence notes

The supplied NVD record states that U-Boot DFU does not bound the USB DFU download setup packet length and does not verify transfer direction, and that a physical attacker can overrun the heap-allocated request buffer when wLength exceeds 4096 bytes. NVD lists the vulnerable CPE range as denx:u-boot from 2012.10 through 2022.07 and assigns CVSS 3.1 vector AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. The record includes references to oss-sec, Debian LTS, and Siemens ProductCERT; the full text of those references is not included in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-2347 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-2347

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-2347 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-2347

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.