CVE-2022-2893: Ronds Equipment Predictive Maintenance

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.  

Affected products

  • Ronds Equipment Predictive Maintenance: version 1.19.5 only

Published 2023-01-17. Last modified 2026-06-17.