CVE-2022-25247: PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25247?
CVE-2022-25247 is a vulnerability in Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) that allows an attacker to send certain commands to a specific port without authentication.
What is the severity of CVE-2022-25247?
CVE-2022-25247 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2022-25247?
An attacker can exploit CVE-2022-25247 by sending certain commands to a specific port without authentication, which can lead to obtaining full file-system access.
Which software versions are affected by CVE-2022-25247?
Axeda agent versions up to exclusive 6.9.1 and Axeda Desktop Server for Windows versions up to exclusive 6.9.215 are affected by CVE-2022-25247.
Where can I find more information about CVE-2022-25247?
You can find more information about CVE-2022-25247 at the following references: [link1](https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01) and [link2](https://www.ptc.com/en/support/article/CS363561).