PatchSiren cyber security CVE debrief
CVE-2022-48174 Siemens CVE debrief
CVE-2022-48174 is a high-severity BusyBox shell vulnerability that Siemens republishes for several industrial networking products in its SINEC OS / SCALANCE / RUGGEDCOM portfolio. The source advisory describes a stack overflow in ash.c:6030 in BusyBox before 1.35, with the potential for arbitrary code execution in the affected environment. Siemens’ remediation is to update affected products to V3.3 or later.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-28
- Original CVE updated
- 2026-02-25
- Advisory published
- 2026-01-28
- Advisory updated
- 2026-02-25
Who should care
OT/ICS defenders, Siemens product owners, plant and infrastructure network administrators, and vulnerability management teams responsible for affected Siemens SINEC OS, SCALANCE, and RUGGEDCOM devices.
Technical summary
The advisory maps CVE-2022-48174 to a BusyBox ash stack overflow (ash.c:6030) present in BusyBox versions before 1.35. The CISA CSAF republication, based on Siemens ProductCERT advisory SSA-089022, lists multiple affected Siemens industrial networking products and states that firmware/update remediation is available. The provided CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating meaningful impact if a local user action can trigger the flaw in the affected deployment.
Defensive priority
High. The CVSS score is 7.8 and the source notes potential arbitrary code execution. In OT environments, even locally triggered flaws can be operationally significant because affected devices may be management-plane or edge components supporting critical connectivity.
Recommended defensive actions
- Identify whether any Siemens devices in scope match the affected product families listed in the advisory.
- Check installed firmware/software versions against Siemens advisory SSA-089022 and CISA advisory ICSA-26-043-06.
- Upgrade affected products to V3.3 or later, per the vendor remediation guidance.
- Prioritize devices that are exposed to administrative users or other local interactive access paths.
- Restrict access to management interfaces and limit who can trigger shell or maintenance functions.
- Apply OT change-control and maintenance-window procedures before remediation, and verify backups and rollback plans.
- Monitor Siemens and CISA advisory updates for any product-scope clarifications or remediation changes.
Evidence notes
This debrief is based only on the supplied CISA CSAF source item and its embedded Siemens references. The source explicitly states the BusyBox ash stack overflow condition, the affected Siemens product families, and the remediation to update to V3.3 or later. The timeline uses the supplied advisory publication and modification dates from the source corpus; no independent disclosure date is inferred.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-48174 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-48174
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-48174 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-48174
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-089022.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-089022.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.