Arbitrary Code Execution Vulnerability in Siemens Networking Products
CVE-2022-34821
8.8HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-34821?
A vulnerability exists in certain Siemens devices that allows an attacker to execute arbitrary code with elevated privileges by injecting malicious commands into specific OpenVPN configuration options. This can lead to significant security risks, potentially allowing unauthorized access to sensitive systems and data.
Affected Version(s)
RUGGEDCOM RM1224 LTE(4G) EU 0
RUGGEDCOM RM1224 LTE(4G) NAM 0
SCALANCE M804PB 0