CVE-2022-2893

RONDS EPM version 1.19.5 does not properly validate the filename 
parameter, which could allow an unauthorized user to specify file paths 
and download files. 



Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
icscertCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CVEADP
---
---
CISA-ADPADP
---
---