# CVE-2022-29898

## Summary

- **CVE ID:** CVE-2022-29898
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-354
- **Published:** May 11, 2022
- **Last Modified:** Mar 13, 2026

## Description

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

## Affected Products

- PHOENIX CONTACT — RAD-ISM-900-EN-BD/B (All Versions)
- PHOENIX CONTACT — RAD-ISM-900-EN-BD (All Versions)
- PHOENIX CONTACT — RAD-ISM-900-EN-BD-BUS (All Versions)

## References

- [CNA](https://cert.vde.com/en/advisories/VDE-2022-018/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.54%
- **EPSS Percentile:** 67.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._