RONDS EPM version 1.19.5 has a vulnerability in which a function could
allow unauthenticated users to leak credentials. In some circumstances,
an attacker can exploit this vulnerability to execute operating system
(OS) commands.
allow unauthenticated users to leak credentials. In some circumstances,
an attacker can exploit this vulnerability to execute operating system
(OS) commands.
Metrics
Affected Vendors & Products
Fixes
Solution
RONDS provides the software to users that purchase their products and recommends users upgrade the software to version 1.35.21.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 |
![]() ![]() |
History
Thu, 16 Jan 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T22:01:20.020Z
Reserved: 2022-09-01T18:59:32.526Z
Link: CVE-2022-3091

Updated: 2024-08-03T01:00:10.612Z

Status : Modified
Published: 2023-01-17T17:15:11.620
Modified: 2024-11-21T07:18:48.483
Link: CVE-2022-3091

No data.

No data.