CVE-2023-27881: PTC Vuforia Studio Unrestricted Upload of File with Dangerous Type
Published Jun 7, 2023
·Updated
A user could use the “Upload Resource” functionality to upload files to any location on the disk.
Affected Software
2 affected components
PTC Vuforia Studio<9.9
PTC Vuforia Studio: all versions prior to 9.9
Remediation
Information
PTC recommends users upgrade to Vuforia Studio release 9.9 https://support.ptc.com/help/vuforia/studio/en/ or higher.
Event History
Jun 7, 2023
CVE Published
via MITRE·09:48 PM
Data Sourced
via MITRE·09:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-27881?
CVE-2023-27881 is a vulnerability that allows a user to upload files to any location on the disk using the “Upload Resource” functionality.
2
How severe is CVE-2023-27881?
CVE-2023-27881 has a severity rating of 9.9 (critical).
3
Which software is affected by CVE-2023-27881?
PTC Vuforia Studio versions up to 9.9 are affected by CVE-2023-27881.
4
How can I fix CVE-2023-27881?
To fix CVE-2023-27881, apply the recommended patches or updates provided by the software vendor.
5
Where can I find more information about CVE-2023-27881?
More information about CVE-2023-27881 can be found at the following references: [link1](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13) and [link2](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13).