Vulnerabilities > Phoenixcontact > RAD ISM 900 EN BD BUS Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-29898 Improper Validation of Integrity Check Value vulnerability in Phoenixcontact products
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
network
low complexity
phoenixcontact CWE-354
critical
9.0
2022-05-11 CVE-2022-29897 Improper Input Validation vulnerability in Phoenixcontact products
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.
network
low complexity
phoenixcontact CWE-20
critical
9.0