← Vulnerability feed

Vulnerability record · CVE-2022-36323 · published 10 August 2022

CVE-2022-36323: Siemens scalance m-800 firmware injection vulnerability

Siemens · Scalance M 800 Firmware

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

9.1 CVSS 3.1 Critical EPSS 1.7% · top 23.5% CWE-74 · Injection
9.1CVSS 3.1 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
90Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

90 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed8.8CVE-2021-25667Siemens ruggedcom rm1224 firmware stack-based buffer overflow vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE…EPSS 0.86%8.7CVE-2020-28400Siemens dk standard ethernet controller evaluation kit firmware allocation without limits vulnerabilityAffected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be t…EPSS 1.9%8.6CVE-2024-50572Siemens ruggedcom rm1224 lte\(4g\) eu firmware injection vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.67%8.6CVE-2024-50557Siemens ruggedcom rm1224 lte\(4g\) eu firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.90%8.6CVE-2022-31766Siemens ruggedcom rm1224 firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…EPSS 1.1%7.8CVE-2022-30065Busybox use after free vulnerabilityA use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the c…EPSS 1.3%7.5CVE-2022-36324Siemens scalance m-800 firmware allocation without limits vulnerabilityAffected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TC…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2022-36323), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.