CVE-2022-29897
Summary
| CVE | CVE-2022-29897 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-11 15:15:00 UTC |
| Updated | 2022-05-20 14:15:00 UTC |
| Description | On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Phoenixcontact | Rad-ism-900-en-bd | - | All | All | All |
| Hardware | Phoenixcontact | Rad-ism-900-en-bd-bus | - | All | All | All |
| Operating System | Phoenixcontact | Rad-ism-900-en-bd-bus Firmware | All | All | All | All |
| Hardware | Phoenixcontact | Rad-ism-900-en-bd/b | - | All | All | All |
| Operating System | Phoenixcontact | Rad-ism-900-en-bd/b Firmware | All | All | All | All |
| Operating System | Phoenixcontact | Rad-ism-900-en-bd Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VDE-2022-018 | CERT@VDE | CONFIRM | cert.vde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: The vulnerabilities were discovered and reported by Logan Carpenter of DRAGOS.
Legacy QID Mappings
- 591316 Phoenix Contact RAD-ISM-900-EN-BD devices Multiple Vulnerabilities (VDE-2022-018)