CVE-2023-29168: PTC Vuforia Studio Insufficiently Protected Credentials
Published Jun 7, 2023
·Updated
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
Affected Software
2 affected components
PTC Vuforia Studio<9.9
PTC Vuforia Studio: all versions prior to 9.9
Remediation
Information
PTC recommends users upgrade to Vuforia Studio release 9.9 https://support.ptc.com/help/vuforia/studio/en/ or higher.
Event History
Jun 7, 2023
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29168.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The local Vuforia web application does not support HTTPS and federated credentials are passed via basic authentication.'
3
Does the local Vuforia web application support HTTPS?
No, the local Vuforia web application does not support HTTPS.
4
How are federated credentials passed in the local Vuforia web application?
Federated credentials are passed via basic authentication in the local Vuforia web application.
5
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.5.