<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:40:54.941865+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-2347</id>
    <title>CVE-2022-2347 — Unchecked Download size in Uboot</title>
    <updated>2026-10-05T20:40:54.959050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Uboot, Siemens RUGGEDCOM ROX MX5000, Siemens RUGGEDCOM ROX MX5000RE, Siemens RUGGEDCOM ROX RX1400, Siemens RUGGEDCOM ROX RX1500, Siemens RUGGEDCOM ROX RX1501, Siemens RUGGEDCOM ROX RX1510, Siemens RUGGEDCOM ROX RX1511, Siemens RUGGEDCOM ROX RX1512, Siemens RUGGEDCOM ROX RX1524 and 2 more</p>
<p>There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-2347"/>
  </entry>
</feed>
