CVE-2022-3091

RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ronds:equipment_predictive_maintenance:1.19.5:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-02 - Third Party Advisory, US Government Resource
Summary
  • (es) RONDS EPM versión 1.19.5 tiene una vulnerabilidad en la que una función podría permitir que usuarios no autenticados filtren credenciales. En algunas circunstancias, un atacante puede aprovechar esta vulnerabilidad para ejecutar comandos del sistema operativo (SO).

Information

Published : 2023-01-17 17:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-3091

Mitre link : CVE-2022-3091

CVE.ORG link : CVE-2022-3091


JSON object : View

Products Affected

ronds

  • equipment_predictive_maintenance
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor