Vulnerabilities (CVE)

Filtered by vendor Ronds Subscribe
Filtered by product Equipment Predictive Maintenance
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2893 1 Ronds 1 Equipment Predictive Maintenance 2024-02-28 N/A 6.5 MEDIUM
RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.  
CVE-2022-3091 1 Ronds 1 Equipment Predictive Maintenance 2024-02-28 N/A 7.5 HIGH
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.