← Back to home
SIEMENS-SSA-254054  ·  Published 2022-10-11  ·  View on Siemens ProductCERT ↗

SSA-254054 V1.3 (Last Update: 2022-10-11): Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products

CVSS 9.8 CRITICAL CISA KEV — Known Exploited

Risk Summary

<p>A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as “Spring4Shell” or “SpringShell”.</p> <p>Siemens has released updates for the affected products and recommends to update to the latest versions.</p>

CVEs (1)

Remediations

  • Refer to Siemens ProductCERT advisory for patch and remediation guidance.

Affected Vendors

Siemens

Affected Products (1)

Siemens · SSA-254054 V1.3 (Last Update: 2022-10-11): Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products See advisory

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more