Vulnerability Description
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ronds | Equipment Predictive Maintenance | 1.19.5 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-3091?
CVE-2022-3091 is a vulnerability with a CVSS score of 7.5 (HIGH). RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute o...
How severe is CVE-2022-3091?
CVE-2022-3091 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3091?
Check the references section above for vendor advisories and patch information. Affected products include: Ronds Equipment Predictive Maintenance.