CVE-2022-3091

RONDS EPM version 1.19.5 has a vulnerability in which a function could 
allow unauthenticated users to leak credentials. In some circumstances, 
an attacker can exploit this vulnerability to execute operating system 
(OS) commands. 



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
rondsequipment_predictive_maintenance
1.19.5
𝑥
= Vulnerable software versions