Unauthenticated User Credential Leakage and OS Command Execution Vulnerability in RONDS EPM Version 1.19.5

Unauthenticated User Credential Leakage and OS Command Execution Vulnerability in RONDS EPM Version 1.19.5

CVE-2022-3091 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.

Learn more about our User Device Pen Test.