LiveActive security incident?Get immediate response
CVE Record

CVE-2022-30790: Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2022-30790 is reported as a buffer overflow in Das U-Boot 2022.01, a bootloader used in embedded and device firmware. Public metadata does not provide CVSS, CWE, or detailed affected product data. Business urgency depends on whether your devices or firmware images include that U-Boot version or affected downstream packages.

Executive priority

Treat this as an exposure-discovery item first, not an emergency deployment trigger. Escalate priority if critical devices run U-Boot 2022.01 or a vendor confirms affected firmware. The absence of CVSS and KEV evidence limits urgency confidence.

Technical view

The CVE record describes a buffer overflow in Das U-Boot 2022.01 and states it is distinct from CVE-2022-30552. The supplied sources include upstream U-Boot tags, an NCC Group advisory, Debian LTS advisory, and Siemens ProductCERT advisory. The bundle does not include exploit details, a CVSS score, or universal fixed versions.

Likely exposure

Most likely exposure is embedded, industrial, IoT, or appliance firmware using Das U-Boot 2022.01 or vendor firmware derived from it. The source bundle does not identify complete affected CPEs or all impacted downstream products.

Exploitation context

No active exploitation is established in the supplied sources, and this CVE is not listed as KEV. Because this is bootloader code, practical impact and exploitability are highly device-specific and depend on vendor configuration, update model, and attacker access assumptions.

Researcher notes

Evidence is thin in the CVE metadata: no CVSS, CWE, CPEs, or bundled fix details. Use the NCC advisory and vendor advisories to determine root cause and fixed versions, but avoid assuming all U-Boot installations are affected without version and vendor confirmation.

Mitigation direction

  • Inventory devices and firmware images for Das U-Boot 2022.01 or derived builds.
  • Check OEM, Debian LTS, Siemens, and U-Boot guidance for applicable fixed firmware or packages.
  • Apply only vendor-supported firmware or package updates for affected assets.
  • Prioritize updates for internet-managed, field-deployed, or difficult-to-recover embedded devices.
  • Track vendor advisories because the CVE metadata lacks complete affected product details.

Validation and detection

  • Confirm U-Boot version strings in firmware build records or software bills of materials.
  • Map asset vendors against Siemens SSA-577017 and other OEM advisories.
  • For Debian-derived systems, compare installed u-boot packages against the Debian LTS advisory.
  • Verify update status through vendor firmware versions, not just operating-system package scans.
  • Document unknown devices for follow-up where bootloader provenance cannot be confirmed.
Prepared
Confidence
low
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-30790 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
5Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.