CVE-2022-25252: PTC Axeda agent and Axeda Desktop Server Improper Check or Handling Of Exceptional Conditions
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to crash the affected product.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25252?
CVE-2022-25252 is a vulnerability in the Axeda agent and Axeda Desktop Server for Windows, which can be exploited remotely by an unauthenticated attacker.
How severe is CVE-2022-25252?
CVE-2022-25252 has a severity score of 7.5, indicating a high severity vulnerability.
Which software versions are affected by CVE-2022-25252?
Axeda agent versions up to and excluding 6.9.1, and Axeda Desktop Server for Windows versions up to and excluding 6.9.215 are affected by CVE-2022-25252.
How can CVE-2022-25252 be exploited?
CVE-2022-25252 can be exploited by sending certain input to the affected services on the specified port.
Are there any references or resources for CVE-2022-25252?
Yes, you can find more information about CVE-2022-25252 at the following references: [1](https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01) and [2](https://www.ptc.com/en/support/article/CS363561).