Junglewise Threat Intelligence

CVE-2022-30790: Das U-Boot buffer overflow in version 2022.01

CVE-2022-30790 · Severity: high · CVSS 7.8 · Published 2022-06-08

Technologies: Das U-Boot U-Boot, Siemens RUGGEDCOM ROX II. Vendors: Denx, Siemens.

Executive brief

Das U-Boot is a widely used open-source bootloader for embedded devices, such as routers, industrial controllers, and IoT hardware. A security flaw has been identified that could allow a local attacker to cause a system crash or potentially execute unauthorized code. This could lead to a complete loss of device availability or unauthorized access to sensitive data stored on the hardware.

Technical details

A buffer overflow vulnerability exists in Das U-Boot version 2022.01 due to an out-of-bounds write (CWE-787). The flaw is distinct from CVE-2022-30552. An attacker with local access and low privileges can exploit this vulnerability to overwrite memory, potentially achieving arbitrary code execution or causing a system crash (denial-of-service). The vulnerability has been observed in downstream implementations, such as Siemens RUGGEDCOM ROX II devices. Patches are available in newer versions of U-Boot and vendor-specific firmware updates like RUGGEDCOM ROX V2.17.1.

Affected products

  • Das U-Boot U-Boot 2022.01
  • Siemens Corproation RUGGEDCOM ROX II family All versions < V2.17.1

Timeline

  • 2022-06-03: disclosed: Technical advisory published by NCC Group
  • 2022-06-08: advisory: NVD published CVE-2022-30790
  • 2025-05-01: patched: Debian LTS security update released
  • 2026-05-12: patched: Siemens released advisory SSA-577017 with fixes for RUGGEDCOM ROX II

References

Related threats