← volver
CVE-2022-25251criticalCWE-306

PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 1.8%
probabilidad de explotación
1.8%top 23% de las CVE
explotación observada
noninguna fuente lo reporta
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H