← Vulnerability feed

Vulnerability record · CVE-2022-46142 · published 13 December 2022

CVE-2022-46142: Siemens ruggedcom rm1224 lte\(4g\) eu firmware insufficiently protected credentials vulnerability

Siemens · Ruggedcom Rm1224 Lte\(4g\) Eu Firmware

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

5.2 CVSS 4.0 Medium EPSS 0.27% · top 82.9% CWE-257 · CWE-257CWE-522 · Insufficiently protected credentials
5.2CVSS 4.0 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
101Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

101 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46142 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2024-50572Siemens ruggedcom rm1224 lte\(4g\) eu firmware injection vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.67%8.6CVE-2024-50557Siemens ruggedcom rm1224 lte\(4g\) eu firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.90%8.6CVE-2024-41976Siemens ruggedcom rm1224 lte\(4g\) eu firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.77%8.6CVE-2022-31766Siemens ruggedcom rm1224 firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…EPSS 1.1%7.3CVE-2024-41977Siemens ruggedcom rm1224 lte\(4g\) eu firmware vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.44%7.1CVE-2024-41978Siemens ruggedcom rm1224 lte\(4g\) eu firmware sensitive information in log file vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.49%7.1CVE-2022-46140Siemens ruggedcom rm1224 lte\(4g\) eu firmware broken cryptographic algorithm vulnerabilityAffected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of th…EPSS 0.24%5.3CVE-2024-50558Siemens ruggedcom rm1224 lte\(4g\) eu firmware improper access control vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2022-46142), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.