Ronds operates in the industrial equipment and predictive-maintenance domain, where its products support condition monitoring and asset lifecycle management. The observed vulnerability signal centers on information-disclosure and path-traversal weaknesses that reflect risks common to web-accessible industrial interfaces and configuration systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ronds over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3091HIGH RONDS EPM version 1.19.5 has a vulnerability in which a function could
allow unauthenticated users to leak credentials. In some circumstances,
an attacker can exploit this vulner | Jan 17, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-2893MEDIUM RONDS EPM version 1.19.5 does not properly validate the filename
parameter, which could allow an unauthorized user to specify file paths
and download files.
| Jan 17, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ronds.
Media articles that mention a CVE ID that affects a product developed by Ronds — matched by CVE ID, not by vendor name.