PatchSiren cyber security CVE debrief
CVE-2022-30790 Siemens CVE debrief
CVE-2022-30790 is a high-severity buffer overflow affecting Denx U-Boot 2022.01. NVD classifies the issue as CWE-787 and rates it 7.8 (CVSS 3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The NVD record also notes that this is a different issue than CVE-2022-30552. Because U-Boot is a bootloader used in embedded and firmware environments, affected systems should be identified and updated using vendor and downstream guidance.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Teams that build, ship, or maintain systems using U-Boot 2022.01 should care most, especially embedded-device vendors, firmware engineers, OEM/ODM maintainers, and downstream distributors such as Linux/firmware package maintainers.
Technical summary
NVD lists CVE-2022-30790 as a buffer overflow in Denx U-Boot 2022.01, mapped to CWE-787. The published CVSS vector indicates a local attack context with low attack complexity and low privileges required, and high impacts to confidentiality, integrity, and availability. NVD references third-party advisories and identifies the vulnerable CPE as cpe:2.3:a:denx:u-boot:2022.01:*:*:*:*:*:*:*.
Defensive priority
High for any environment that ships or depends on U-Boot 2022.01. Even with local attack conditions in the CVSS vector, bootloader vulnerabilities can be consequential in device supply chains and firmware maintenance paths.
Recommended defensive actions
- Inventory all products, images, and firmware builds that include U-Boot 2022.01.
- Check vendor and downstream advisories for patched U-Boot releases and upgrade guidance.
- Prioritize remediation in devices that can receive firmware updates and in products exposed to untrusted local access.
- Validate that any affected bootloader builds are replaced or rebuilt from a fixed U-Boot version before shipment.
- Track downstream maintainer notices for packaged firmware or board-support updates related to this CVE.
Evidence notes
This debrief is based on the NVD record for CVE-2022-30790, which published on 2022-06-08 and was modified on 2026-05-12. Evidence includes the NVD CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), CWE-787 classification, vulnerable CPE for Denx U-Boot 2022.01, and NVD-linked references to NCC Group, GitHub tags, Debian LTS, and Siemens CERT. The description supplied by NVD states that this is a different issue than CVE-2022-30552.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-30790 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-30790
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-30790 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30790
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.