CVE-2024-40395: Medium severity PTC ThingWorx vulnerability
Published Aug 27, 2024
·Updated
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
Affected Software
1 affected component
PTC ThingWorx=9.5.0
Event History
Aug 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40395?
CVE-2024-40395 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2024-40395?
To fix CVE-2024-40395, upgrade PTC ThingWorx to version 9.5.1 or later where the vulnerability is addressed.
3
What type of vulnerability is CVE-2024-40395?
CVE-2024-40395 is an Insecure Direct Object Reference (IDOR) vulnerability.
4
What data can be exposed due to CVE-2024-40395?
CVE-2024-40395 can allow attackers to access sensitive information, including personally identifiable information (PII).
5
Which version of PTC ThingWorx is affected by CVE-2024-40395?
CVE-2024-40395 affects PTC ThingWorx version 9.5.0.