CVE-2023-29502: PTC Vuforia Studio Path Traversal
Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-29502?
CVE-2023-29502 is a vulnerability that allows a user to modify the "resourceDirectory" attribute in the appConfig.json file before importing a project into Vuforia.
How does CVE-2023-29502 affect PTC Vuforia Studio?
CVE-2023-29502 affects PTC Vuforia Studio by allowing a user to modify the "resourceDirectory" attribute in the appConfig.json file.
What is the severity of CVE-2023-29502?
The severity of CVE-2023-29502 is medium with a CVSS score of 4.3.
How can I fix CVE-2023-29502?
To fix CVE-2023-29502, it is recommended to apply the necessary patches or updates provided by PTC Vuforia Studio.
Is there any additional information about CVE-2023-29502?
For more information about CVE-2023-29502, you can refer to the official advisories published by CISA: [link1](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13) and [link2](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-13).