CVE-2022-25251: PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25251?
CVE-2022-25251 is a vulnerability that allows an attacker to send certain XML messages to a specific port without proper authentication in Axeda agent and Axeda Desktop Server for Windows, potentially leading to remote unauthorized access.
What is the severity of CVE-2022-25251?
The severity of CVE-2022-25251 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-25251?
Axeda agent versions up to 6.9.1 and Axeda Desktop Server for Windows versions up to 6.9.215 are affected by CVE-2022-25251.
How can an attacker exploit CVE-2022-25251?
An attacker can exploit CVE-2022-25251 by sending certain XML messages to a specific port without proper authentication, potentially allowing remote unauthorized access.
Are there any references for CVE-2022-25251?
Yes, you can refer to the following resources for more information about CVE-2022-25251: [Link 1](https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01), [Link 2](https://www.ptc.com/en/support/article/CS363561).