CVE-2022-25246: PTC Axeda agent and Axeda Desktop Server Use of Hard-Coded Credentials
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25246?
CVE-2022-25246 refers to a vulnerability in the Axeda agent and Axeda Desktop Server for Windows where hard-coded credentials are used for UltraVNC installation, allowing a remote attacker to take control of the host operating system.
How severe is CVE-2022-25246?
CVE-2022-25246 has a severity rating of 8.8 (critical).
Which software versions are affected by CVE-2022-25246?
Axeda agent versions up to and excluding 6.9.1, and Axeda Desktop Server for Windows versions up to and excluding 6.9.215 are affected by CVE-2022-25246.
How can a remote attacker exploit CVE-2022-25246?
A remote authenticated attacker can exploit CVE-2022-25246 by using the hard-coded credentials to gain full remote control of the host operating system.
Are there any references for CVE-2022-25246?
Yes, you can find references for CVE-2022-25246 at the following links: - [US-CERT Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01) - [PTC Support Article](https://www.ptc.com/en/support/article/CS363561)