CVE-2022-34821
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jul 12, 2022
Updated: Jan 14, 2025
CWE ID 94
Summary
CVE-2022-34821 is a vulnerability affecting various RUGGEDCOM and Siemens SIMATIC products, including but not limited to RM1224 LTE routers, SCALANCE M, WAM, and WUB series routers, and SIMATIC CP series controllers. The issue arises from the ability for an attacker to inject code into specific OpenVPN configuration options, resulting in the execution of arbitrary code with elevated privileges. Impacted devices should be updated as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Siemens AG