CVE-2022-25251
PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration.
Cuando es conectado a un determinado puerto Axeda agent (Todas las versiones) y Axeda Desktop Server para Windows (Todas las versiones) pueden permitir a un atacante enviar determinados mensajes XML a un puerto específico sin la debida autenticación. Una explotación con éxito de esta vulnerabilidad podría permitir a un atacante remoto no autenticado leer y modificar la configuración del producto afectado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-16 CVE Reserved
- 2022-03-16 CVE Published
- 2024-05-30 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ptc.com/en/support/article/CS363561 | 2022-03-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ptc Search vendor "Ptc" | Axeda Agent Search vendor "Ptc" for product "Axeda Agent" | < 6.9.1 Search vendor "Ptc" for product "Axeda Agent" and version " < 6.9.1" | - |
Affected
| ||||||
Ptc Search vendor "Ptc" | Axeda Desktop Server Search vendor "Ptc" for product "Axeda Desktop Server" | < 6.9.215 Search vendor "Ptc" for product "Axeda Desktop Server" and version " < 6.9.215" | windows |
Affected
|