CVE-2022-30552 is a buffer overflow vulnerability affecting Das U-Boot 2022.01, a widely used bootloader for embedded systems. Rated Medium (CVSS 5.5), this local vulnerability requires low privileges and local access, but can lead to a high impact on availability, potentially allowing for system compromise. While not currently listed in CISA's KEV catalog, community discussions and media coverage indicate significant attention, with reports of a remote write anywhere primitive in its IP stack. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2022.01CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.01:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.