PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-30552 Siemens CVE debrief

CVE-2022-30552 is a buffer overflow in Denx U-Boot 2022.01. NVD scores it 5.5/Medium and classifies the issue as locally exploitable with low privileges and no user interaction, with a primary impact on availability. For embedded and firmware teams, the main concern is denial of service or boot disruption in devices that ship or embed the affected U-Boot release.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Embedded device vendors, OEM firmware teams, bootloader maintainers, and operators responsible for products that ship Denx U-Boot 2022.01 should review this issue. It matters most where local, console, maintenance, or recovery access is possible.

Technical summary

The NVD entry maps this issue to CWE-120 (buffer overflow) in U-Boot 2022.01. The published vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local attacker with low privileges and no user interaction may be able to trigger an availability-impacting failure. The supplied corpus does not provide deeper implementation detail, so defenders should treat affected firmware as needing vendor confirmation and patch verification rather than assuming identical exposure in every product.

Defensive priority

Medium. The CVSS score is 5.5, but the issue can affect bootloader availability in embedded environments, where a crash or failed boot can have outsized operational impact.

Recommended defensive actions

  • Inventory products and firmware images that include U-Boot 2022.01 or a vendor-derived build.
  • Check the linked U-Boot release tags and vendor advisories to identify the fixed release for your platform.
  • Apply vendor-provided firmware updates that include a patched U-Boot build.
  • Restrict local, physical, console, and recovery-path access to affected devices until they are updated.
  • Validate the update across all device variants, boot paths, and recovery images before broad rollout.
  • Monitor for boot failures or maintenance-console instability after remediation to confirm the fix is effective.

Evidence notes

The supplied NVD record identifies CVE-2022-30552 as affecting cpe:2.3:a:denx:u-boot:2022.01 and classifies it with CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-120. The record also links to U-Boot release tags, an NCC Group technical advisory, Debian LTS, and Siemens ProductCERT materials. The supplied enrichment does not mark this CVE as KEV or associated with a ransomware campaign.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-30552 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-30552

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-30552 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30552

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.