{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3osiemensscalance_sc646-2c_firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc622-2c_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc626-2c_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc636-2c_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc642-2c_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2022-30065"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BusyBox (\u003c 1.35.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BusyBox"],"content_html":"\u003cp\u003eBusyBox, a widely used suite of Unix utilities for embedded Linux systems, contains a heap-based buffer overflow vulnerability identified as CVE-2022-30065. This vulnerability impacts versions of BusyBox prior to 1.35.0. An attacker with local access to a system running an affected version can exploit this flaw to execute arbitrary code. By triggering the buffer overflow during specific command processing operations, an attacker can overwrite memory regions to divert the execution flow of the BusyBox binary. This is particularly critical in embedded environments where BusyBox often runs with elevated privileges or provides essential system administration functions. Defenders should prioritize patching BusyBox in firmware and container images.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to achieve arbitrary code execution on the target system. This can lead to full system compromise, unauthorized data access, and disruption of service. Given the prevalence of BusyBox in embedded devices, routers, and minimal Linux environments, the scope of potential impact is significant, particularly in IoT and infrastructure sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate BusyBox to version 1.35.0 or later across all firmware, container images, and embedded Linux systems. Monitor for unauthorized or abnormal local process execution patterns using auditd or similar endpoint monitoring tools to detect exploitation attempts that trigger crashes or abnormal utility behavior.\u003c/p\u003e\n","date_modified":"2026-09-16T13:11:24Z","date_published":"2026-09-16T13:11:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-busybox-rce/","summary":"A heap-based buffer overflow vulnerability (CVE-2022-30065) in BusyBox allows a local attacker to execute arbitrary code and compromise system integrity.","title":"Arbitrary Code Execution in BusyBox via Heap Buffer Overflow","url":"https://feed.craftedsignal.io/briefs/2026-09-busybox-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}