CWE
94
Advisory Published
Updated

CVE-2022-34821: Code Injection

First published: Tue Jul 12 2022(Updated: )

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2), SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2), SCALANCE M874-2 (6GK5874-2AA00-2AA2), SCALANCE M874-3 (6GK5874-3AA00-2AA2), SCALANCE M876-3 (6GK5876-3AA02-2BA2), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2), SCALANCE M876-4 (6GK5876-4AA10-2BA2), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC622-2C (6GK5622-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC626-2C (6GK5626-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC632-2C (6GK5632-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC636-2C (6GK5636-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC642-2C (6GK5642-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE SC646-2C (6GK5646-2GS00-2AC2), SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0), SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0), SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0), SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0), SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0), SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0), SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0), SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0), SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0). By injecting code to specific configuration options for OpenVPN, an attacker could execute arbitrary code with elevated privileges.

Credit: productcert@siemens.com productcert@siemens.com

Affected SoftwareAffected VersionHow to fix
All of
Siemens Simatic Net CP 1242-7 Firmware
Siemens SIMATIC CP 1242-7 V2 firmware
All of
siemens simatic cp 1243-1 firmware
siemens simatic cp 1243-1
All of
Siemens SIMATIC CP 1243-7 LTE
Siemens SIMATIC NET CP 1243-7 LTE EU
All of
Siemens SIMATIC CP 1243-7 LTE
Siemens SIMATIC NET CP 1243-7 LTE US
All of
Siemens SIMATIC CP 1243-8 IRC
Siemens SIMATIC CP 1243-8 IRC Firmware
All of
siemens simatic cp 1542sp-1 irc firmware>=2.0
siemens simatic cp 1542sp-1 irc
All of
siemens simatic cp 1543-1 firmware<3.0.22
siemens simatic cp 1543-1
All of
siemens simatic cp 1543sp-1 firmware>=2.0
siemens simatic cp 1543sp-1
All of
siemens siplus et 200sp cp 1542sp-1 irc tx rail firmware>=2.0
siemens siplus et 200sp cp 1542sp-1 irc tx rail
All of
siemens siplus et 200sp cp 1543sp-1 isec firmware>=2.0
siemens siplus et 200sp cp 1543sp-1 isec
All of
siemens siplus et 200sp cp 1543sp-1 isec tx rail firmware>=2.0
siemens siplus et 200sp cp 1543sp-1 isec tx rail
All of
Siemens SIPLUS NET CP 1242-7 V2
Siemens SIPLUS NET CP 1242-7 V2
All of
siemens siplus net cp 1543-1 firmware<3.0.22
siemens siplus net cp 1543-1
All of
siemens siplus s7-1200 cp 1243-1 firmware
siemens siplus s7-1200 cp 1243-1
All of
siemens siplus s7-1200 cp 1243-1 rail firmware
siemens siplus s7-1200 cp 1243-1 rail
Siemens Simatic Net CP 1242-7 Firmware
Siemens SIMATIC CP 1242-7 V2 firmware
siemens simatic cp 1243-1 firmware
siemens simatic cp 1243-1
Siemens SIMATIC CP 1243-7 LTE
Siemens SIMATIC NET CP 1243-7 LTE EU
Siemens SIMATIC CP 1243-7 LTE
Siemens SIMATIC NET CP 1243-7 LTE US
Siemens SIMATIC CP 1243-8 IRC
Siemens SIMATIC CP 1243-8 IRC Firmware
siemens simatic cp 1542sp-1 irc firmware>=2.0
siemens simatic cp 1542sp-1 irc
siemens simatic cp 1543-1 firmware<3.0.22
siemens simatic cp 1543-1
siemens simatic cp 1543sp-1 firmware>=2.0
siemens simatic cp 1543sp-1
siemens siplus et 200sp cp 1542sp-1 irc tx rail firmware>=2.0
siemens siplus et 200sp cp 1542sp-1 irc tx rail
siemens siplus et 200sp cp 1543sp-1 isec firmware>=2.0
siemens siplus et 200sp cp 1543sp-1 isec
siemens siplus et 200sp cp 1543sp-1 isec tx rail firmware>=2.0
siemens siplus et 200sp cp 1543sp-1 isec tx rail
Siemens SIPLUS NET CP 1242-7 V2
Siemens SIPLUS NET CP 1242-7 V2
siemens siplus net cp 1543-1 firmware<3.0.22
siemens siplus net cp 1543-1
siemens siplus s7-1200 cp 1243-1 firmware
siemens siplus s7-1200 cp 1243-1
siemens siplus s7-1200 cp 1243-1 rail firmware
siemens siplus s7-1200 cp 1243-1 rail

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-34821?

    The severity of CVE-2022-34821 is critical.

  • What is the affected software for CVE-2022-34821?

    The affected software for CVE-2022-34821 includes RUGGEDCOM RM1224 LTE(4G) EU, RUGGEDCOM RM1224 LTE(4G) NAM, SCALANCE M804PB, SCALANCE M812-1 ADSL-Router (Annex A), and SCALANCE M812-1 ADSL-Router (Annex B) with versions below V7.2.

  • How can I fix CVE-2022-34821?

    To fix CVE-2022-34821, it is recommended to update the affected software to version V7.2 or higher.

  • Where can I find more information about CVE-2022-34821?

    You can find more information about CVE-2022-34821 in the following references: [link1], [link2].

  • What is the Common Vulnerabilities and Exposures (CVE) ID of this vulnerability?

    The Common Vulnerabilities and Exposures (CVE) ID of this vulnerability is CVE-2022-34821.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203