First published: Wed Jun 07 2023(Updated: )
A user could use the “Upload Resource” functionality to upload files to any location on the disk.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
PTC Vuforia Studio | <9.9 | |
PTC Vuforia Studio: all versions prior to 9.9 |
PTC recommends users upgrade to Vuforia Studio release 9.9 https://support.ptc.com/help/vuforia/studio/en/ or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27881 is a vulnerability that allows a user to upload files to any location on the disk using the “Upload Resource” functionality.
CVE-2023-27881 has a severity rating of 9.9 (critical).
PTC Vuforia Studio versions up to 9.9 are affected by CVE-2023-27881.
To fix CVE-2023-27881, apply the recommended patches or updates provided by the software vendor.
More information about CVE-2023-27881 can be found at the following references: [link1](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13) and [link2](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13).