Description
RONDS EPM version 1.19.5 does not properly validate the filename
parameter, which could allow an unauthorized user to specify file paths
and download files.  



Published: 2023-01-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

RONDS provides the software to users that purchase their products and recommends users upgrade the software to version 1.35.21.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-35122 RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.  
History

Thu, 16 Jan 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ronds Equipment Predictive Maintenance
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T22:01:26.105Z

Reserved: 2022-08-18T22:34:51.784Z

Link: CVE-2022-2893

cve-icon Vulnrichment

Updated: 2024-08-03T00:53:00.205Z

cve-icon NVD

Status : Modified

Published: 2023-01-17T17:15:11.333

Modified: 2024-11-21T07:01:53.153

Link: CVE-2022-2893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses