Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gg9m-7hf2-hmp9

Опубликовано: 12 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

EPSS

Процентиль: 67%
0.00539
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

CVSS3: 9.1
fstec
больше 3 лет назад

Уязвимость загрузчика файла конфигурации WebUI устройств PHOENIX CONTACT RAD-ISM-900-EN-*, позволяющая нарушителю выполнить произвольный код с root-привилегиями

EPSS

Процентиль: 67%
0.00539
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-354