CVE-2022-25250: PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25250?
CVE-2022-25250 is a vulnerability found in Axeda agent and Axeda Desktop Server for Windows, which allows an attacker to send a specific command to a port without authentication.
What is the severity of CVE-2022-25250?
The severity of CVE-2022-25250 is high, with a severity value of 7.5.
How does CVE-2022-25250 impact Axeda agent?
CVE-2022-25250 impacts Axeda agent by allowing an attacker to send a certain command to a specific port without authentication.
How does CVE-2022-25250 impact Axeda Desktop Server for Windows?
CVE-2022-25250 impacts Axeda Desktop Server for Windows by allowing an attacker to send a certain command to a specific port without authentication.
How can I mitigate CVE-2022-25250?
To mitigate CVE-2022-25250, it is recommended to update Axeda agent to version 6.9.1 or later, and Axeda Desktop Server for Windows to version 6.9.215 or later.