RONDS EPM version 1.19.5 does not properly validate the filename
parameter, which could allow an unauthorized user to specify file paths
and download files.
parameter, which could allow an unauthorized user to specify file paths
and download files.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35122 | RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files. |
Fixes
Solution
RONDS provides the software to users that purchase their products and recommends users upgrade the software to version 1.35.21.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 |
|
History
Thu, 16 Jan 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T22:01:26.105Z
Reserved: 2022-08-18T22:34:51.784Z
Link: CVE-2022-2893
Updated: 2024-08-03T00:53:00.205Z
Status : Modified
Published: 2023-01-17T17:15:11.333
Modified: 2024-11-21T07:01:53.153
Link: CVE-2022-2893
No data.
OpenCVE Enrichment
No data.
EUVD