<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3osiemensscalance_sc632-2c_firmware/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 13:11:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3osiemensscalance_sc632-2c_firmware/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Code Execution in BusyBox via Heap Buffer Overflow</title><link>https://feed.craftedsignal.io/briefs/2026-09-busybox-rce/</link><pubDate>Wed, 16 Sep 2026 13:11:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-busybox-rce/</guid><description>A heap-based buffer overflow vulnerability (CVE-2022-30065) in BusyBox allows a local attacker to execute arbitrary code and compromise system integrity.</description><content:encoded><![CDATA[<p>BusyBox, a widely used suite of Unix utilities for embedded Linux systems, contains a heap-based buffer overflow vulnerability identified as CVE-2022-30065. This vulnerability impacts versions of BusyBox prior to 1.35.0. An attacker with local access to a system running an affected version can exploit this flaw to execute arbitrary code. By triggering the buffer overflow during specific command processing operations, an attacker can overwrite memory regions to divert the execution flow of the BusyBox binary. This is particularly critical in embedded environments where BusyBox often runs with elevated privileges or provides essential system administration functions. Defenders should prioritize patching BusyBox in firmware and container images.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local attacker to achieve arbitrary code execution on the target system. This can lead to full system compromise, unauthorized data access, and disruption of service. Given the prevalence of BusyBox in embedded devices, routers, and minimal Linux environments, the scope of potential impact is significant, particularly in IoT and infrastructure sectors.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update BusyBox to version 1.35.0 or later across all firmware, container images, and embedded Linux systems. Monitor for unauthorized or abnormal local process execution patterns using auditd or similar endpoint monitoring tools to detect exploitation attempts that trigger crashes or abnormal utility behavior.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>