PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-31765 Siemens CVE debrief

CVE-2022-31765 is a high-severity privilege-escalation issue in Siemens SCALANCE wireless devices. CISA published the advisory on 2026-04-14 and republished it on 2026-04-21 from Siemens ProductCERT SSA-019200. The supplied advisory text says the web interface’s change-password function is not properly authorized, and the supplied enrichment does not mark this CVE as a CISA KEV item.

Vendor
Siemens
Product
SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0)
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-14
Original CVE updated
2026-04-21
Advisory published
2026-04-14
Advisory updated
2026-04-21

Who should care

OT/ICS operators, network administrators, and Siemens SCALANCE owners managing the listed W7xx wireless devices, especially anyone exposing the web management interface.

Technical summary

The advisory states that affected devices do not properly authorize the web interface’s change-password function. That means a low-privileged user could abuse the flaw to escalate privileges on the device. The supplied advisory assigns CVSS 3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and indicates affected versions are earlier than 6.6.0. Siemens’ remediation is to update to V6.6.0 or later.

Defensive priority

High: prioritize patching affected devices, especially if the management interface is reachable from any network segment accessible to low-privileged users.

Recommended defensive actions

  • Update affected Siemens SCALANCE devices to V6.6.0 or later, per the vendor remediation in the supplied advisory.
  • Inventory SCALANCE W7xx devices and verify exact model/version against the affected product list before scheduling maintenance.
  • Restrict access to the device web interface to trusted administrative networks only.
  • Review accounts and privilege assignments on affected devices to ensure low-privileged users cannot reach administrative password-change functions.
  • Monitor for unauthorized configuration or credential changes on exposed devices until remediation is complete.

Evidence notes

Primary evidence is the CISA CSAF advisory ICSA-26-111-07, which republishes Siemens ProductCERT SSA-019200. The source text explicitly states: 'Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.' The same source provides the CVSS vector (8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and the remediation to update to V6.6.0 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-31765 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-31765

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-31765 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-31765

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-019200.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-019200.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.