PatchSiren cyber security CVE debrief
CVE-2022-30552 Siemens CVE debrief
CVE-2022-30552 is a buffer overflow in Denx U-Boot 2022.01. NVD scores it 5.5/Medium and classifies the issue as locally exploitable with low privileges and no user interaction, with a primary impact on availability. For embedded and firmware teams, the main concern is denial of service or boot disruption in devices that ship or embed the affected U-Boot release.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Embedded device vendors, OEM firmware teams, bootloader maintainers, and operators responsible for products that ship Denx U-Boot 2022.01 should review this issue. It matters most where local, console, maintenance, or recovery access is possible.
Technical summary
The NVD entry maps this issue to CWE-120 (buffer overflow) in U-Boot 2022.01. The published vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local attacker with low privileges and no user interaction may be able to trigger an availability-impacting failure. The supplied corpus does not provide deeper implementation detail, so defenders should treat affected firmware as needing vendor confirmation and patch verification rather than assuming identical exposure in every product.
Defensive priority
Medium. The CVSS score is 5.5, but the issue can affect bootloader availability in embedded environments, where a crash or failed boot can have outsized operational impact.
Recommended defensive actions
- Inventory products and firmware images that include U-Boot 2022.01 or a vendor-derived build.
- Check the linked U-Boot release tags and vendor advisories to identify the fixed release for your platform.
- Apply vendor-provided firmware updates that include a patched U-Boot build.
- Restrict local, physical, console, and recovery-path access to affected devices until they are updated.
- Validate the update across all device variants, boot paths, and recovery images before broad rollout.
- Monitor for boot failures or maintenance-console instability after remediation to confirm the fix is effective.
Evidence notes
The supplied NVD record identifies CVE-2022-30552 as affecting cpe:2.3:a:denx:u-boot:2022.01 and classifies it with CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-120. The record also links to U-Boot release tags, an NCC Group technical advisory, Debian LTS, and Siemens ProductCERT materials. The supplied enrichment does not mark this CVE as KEV or associated with a ransomware campaign.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-30552 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-30552
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-30552 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30552
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.