First published: Wed Jun 07 2023(Updated: )
Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
PTC Vuforia Studio | <9.9 | |
PTC Vuforia Studio: all versions prior to 9.9 |
PTC recommends users upgrade to Vuforia Studio release 9.9 https://support.ptc.com/help/vuforia/studio/en/ or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29502 is a vulnerability that allows a user to modify the "resourceDirectory" attribute in the appConfig.json file before importing a project into Vuforia.
CVE-2023-29502 affects PTC Vuforia Studio by allowing a user to modify the "resourceDirectory" attribute in the appConfig.json file.
The severity of CVE-2023-29502 is medium with a CVSS score of 4.3.
To fix CVE-2023-29502, it is recommended to apply the necessary patches or updates provided by PTC Vuforia Studio.
For more information about CVE-2023-29502, you can refer to the official advisories published by CISA: [link1](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13) and [link2](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13).