CVE Database
/

CVE-2022-34821

Back to search

CVE-2022-34821

Published: Jul 12, 2022

Modified: Apr 21, 2025

PUBLISHED

CVSS v3.1

7.6

HIGH

Description

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2), SCALANCE M874-2 (6GK5874-2AA00-2AA2), SCALANCE M874-3 (6GK5874-3AA00-2AA2), SCALANCE M876-3 (6GK5876-3AA02-2BA2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2), SCALANCE M876-4 (6GK5876-4AA10-2BA2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0), SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0), SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0), SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0), SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0), SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0), SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0), SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0), SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0). By injecting code to specific configuration options for OpenVPN, an attacker could execute arbitrary code with elevated privileges.

VendorProductVersions

Siemens

RUGGEDCOM RM1224 LTE(4G) EU

affected
0 - < V7.2

Siemens

RUGGEDCOM RM1224 LTE(4G) NAM

affected
0 - < V7.2

Siemens

SCALANCE M804PB

affected
0 - < V7.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V7.2

Siemens

SCALANCE M812-1 ADSL-Router

affected
0 - < V7.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V7.2

Siemens

SCALANCE M816-1 ADSL-Router

affected
0 - < V7.2

Siemens

SCALANCE M826-2 SHDSL-Router

affected
0 - < V7.2

Siemens

SCALANCE M874-2

affected
0 - < V7.2

Siemens

SCALANCE M874-3

affected
0 - < V7.2

Siemens

SCALANCE M876-3

affected
0 - < V7.2

Siemens

SCALANCE M876-3 (ROK)

affected
0 - < V7.2

Siemens

SCALANCE M876-4

affected
0 - < V7.2

Siemens

SCALANCE M876-4 (EU)

affected
0 - < V7.2

Siemens

SCALANCE M876-4 (NAM)

affected
0 - < V7.2

Siemens

SCALANCE MUM853-1 (EU)

affected
0 - < V7.2

Siemens

SCALANCE MUM856-1 (EU)

affected
0 - < V7.2

Siemens

SCALANCE MUM856-1 (RoW)

affected
0 - < V7.2

Siemens

SCALANCE S615 EEC LAN-Router

affected
0 - < V7.2

Siemens

SCALANCE S615 LAN-Router

affected
0 - < V7.2

Siemens

SCALANCE SC622-2C

affected
0 - < V2.3

Siemens

SCALANCE SC622-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE SC626-2C

affected
0 - < V2.3

Siemens

SCALANCE SC626-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE SC632-2C

affected
0 - < V2.3

Siemens

SCALANCE SC632-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE SC636-2C

affected
0 - < V2.3

Siemens

SCALANCE SC636-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE SC642-2C

affected
0 - < V2.3

Siemens

SCALANCE SC642-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE SC646-2C

affected
0 - < V2.3

Siemens

SCALANCE SC646-2C

affected
V2.3 - < V3.0

Siemens

SCALANCE WAB762-1

affected
0 - < V3.0.0

Siemens

SCALANCE WAM763-1

affected
0 - < V3.0.0

Siemens

SCALANCE WAM763-1 (ME)

affected
0 - < V3.0.0

Siemens

SCALANCE WAM763-1 (US)

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1 (ME)

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1 (US)

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1 EEC

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1 EEC (ME)

affected
0 - < V3.0.0

Siemens

SCALANCE WAM766-1 EEC (US)

affected
0 - < V3.0.0

Siemens

SCALANCE WUB762-1

affected
0 - < V3.0.0

Siemens

SCALANCE WUB762-1 iFeatures

affected
0 - < V3.0.0

Siemens

SCALANCE WUM763-1

affected
0 - < V3.0.0

Siemens

SCALANCE WUM763-1

affected
0 - < V3.0.0

Siemens

SCALANCE WUM763-1 (US)

affected
0 - < V3.0.0

Siemens

SCALANCE WUM763-1 (US)

affected
0 - < V3.0.0

Siemens

SCALANCE WUM766-1

affected
0 - < V3.0.0

Siemens

SCALANCE WUM766-1 (ME)

affected
0 - < V3.0.0

Siemens

SCALANCE WUM766-1 (USA)

affected
0 - < V3.0.0

Siemens

SIMATIC CP 1242-7 V2

affected
All versions < V3.3.46

Siemens

SIMATIC CP 1243-1

affected
All versions < V3.3.46

Siemens

SIMATIC CP 1243-7 LTE EU

affected
All versions < V3.3.46

Siemens

SIMATIC CP 1243-7 LTE US

affected
All versions < V3.3.46

Siemens

SIMATIC CP 1243-8 IRC

affected
All versions < V3.3.46

Siemens

SIMATIC CP 1542SP-1 IRC

affected
V2.0 - < V2.2.28

Siemens

SIMATIC CP 1543-1

affected
All versions < V3.0.22

Siemens

SIMATIC CP 1543SP-1

affected
V2.0 - < V2.2.28

Siemens

SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL

affected
V2.0 - < V2.2.28

Siemens

SIPLUS ET 200SP CP 1543SP-1 ISEC

affected
V2.0 - < V2.2.28

Siemens

SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL

affected
V2.0 - < V2.2.28

Siemens

SIPLUS NET CP 1242-7 V2

affected
All versions < V3.3.46

Siemens

SIPLUS NET CP 1543-1

affected
All versions < V3.0.22

Siemens

SIPLUS S7-1200 CP 1243-1

affected
All versions < V3.3.46

Siemens

SIPLUS S7-1200 CP 1243-1 RAIL

affected
All versions < V3.3.46

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

High

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now