April 19, 2022, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as “Spring4Shell” or “SpringShell”.


Siemens is currently investigating to determine which products are affected and is continuously updating this advisory as more information becomes available.


Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for …

attackers code cve cve-2022-22965 framework impact products siemens spring spring4shell spring framework springshell ssa systems unauthenticated vulnerability vulnerable

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Information System Security Officer (ISSO)

@ LinQuest | Boulder, Colorado, United States

Project Manager - Security Engineering

@ MongoDB | New York City

Security Continuous Improvement Program Manager (m/f/d)

@ METRO/MAKRO | Düsseldorf, Germany

Senior JavaScript Security Engineer, Tools

@ MongoDB | New York City

Principal Platform Security Architect

@ Microsoft | Redmond, Washington, United States

Staff Cyber Security Engineer (Emerging Platforms)

@ NBCUniversal | Englewood Cliffs, NEW JERSEY, United States