10
CVE-2022-25247
- EPSS 2.26%
- Veröffentlicht 16.03.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:51:52
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ptc ≫ Axeda Agent Version < 6.9.1
Ptc ≫ Axeda Desktop Server SwPlatformwindows Version < 6.9.215
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.26% | 0.841 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| ics-cert@hq.dhs.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.