CVE-2022-28391
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose t...
Affects 1 product across 3 vendors.
CVE-2022-28391 affects BusyBox versions up to 1.35.0, allowing remote attackers to execute arbitrary code when netstat is used to print a DNS PTR record's value to a VT compatible terminal. This vulnerability has a CVSS score of 8.8, indicating high severity. The affected vendors include Busybox, Fujitsu-Siemens, and Siemens. No public proof of concept or exploit is available, and the EPSS score suggests a low likelihood of exploitation in the wild.
BSID: BS-2022-GLOBAL-069531-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-28391?
What is the CVSS score for CVE-2022-28391?
Is CVE-2022-28391 actively exploited?
How do I remediate CVE-2022-28391?
What systems are affected by CVE-2022-28391?
What NERC-CIP standard applies to CVE-2022-28391?
What IEC 62443 requirement maps to CVE-2022-28391?
| CVE ID | CVE-2022-28391 |
|---|---|
| BSID | BS-2022-GLOBAL-069531-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Published | 2022-04-03 |
| Last Modified | 2025-06-09 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited by a remote attacker who can manipulate DNS PTR records. When the netstat command is used to display these records on a VT compatible terminal, the attacker can inject malicious code that is executed with the privileges of the user running netstat. This can lead to unauthorized access, data manipulation, and potential system compromise.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Busybox | Busybox | — |
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation to isolate critical systems from untrusted networks. Use DNSSEC to ensure the integrity of DNS responses. Regularly update BusyBox to the latest version to mitigate known vulnerabilities.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to critical cyber assets, which can compromise the reliability and security of the power grid.
This CVE maps to SR 7.6 because it involves the protection of communication channels against unauthorized access and manipulation, which is essential for maintaining the security of industrial control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 85e56aec01bd8e61e9e2258fb1613a1714f9008d8c96890a4be3bfe1ba975a03673543061f44ec5fe8e9c54ac36c9e765ba32940a9da08a1b6eab6f0f32f36d5 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →