CVE-2022-25249: PTC Axeda agent and Axeda Desktop Server Path Traversal
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server..
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25249?
CVE-2022-25249 is a vulnerability that affects Axeda agent and Axeda Desktop Server for Windows, allowing a remote unauthenticated attacker to obtain file system read access via web server.
Which software versions are affected by CVE-2022-25249?
CVE-2022-25249 affects all versions of Axeda agent (up to version 6.9.1) and Axeda Desktop Server for Windows (up to version 6.9.215), except Axeda agent versions 6.9.2 and 6.9.3.
What is the severity of CVE-2022-25249?
CVE-2022-25249 has a severity rating of high with a score of 7.5.
How can a remote attacker exploit CVE-2022-25249?
A remote unauthenticated attacker can exploit CVE-2022-25249 through directory traversal to obtain file system read access via the web server.
Are there any recommended mitigations for CVE-2022-25249?
It is recommended to update Axeda agent to version 6.9.2 or later and Axeda Desktop Server for Windows to version 6.9.3 or later to mitigate the vulnerability.