Vulnerabilities > CVE-2022-38773 - Unspecified vulnerability in Siemens products

047910
CVSS 6.8 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
siemens

Summary

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

Vulnerable Configurations

Part Description Count
OS
Siemens
70
Hardware
Siemens
70