Vulnerabilities > PTC

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-40395 Authorization Bypass Through User-Controlled Key vulnerability in PTC Thingworx 9.5.0
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
network
low complexity
ptc CWE-639
6.5
2024-01-10 CVE-2023-29445 Uncontrolled Search Path Element vulnerability in PTC products
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.
local
low complexity
ptc CWE-427
7.8
2024-01-10 CVE-2023-29446 Improper Input Validation vulnerability in PTC products
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file.
local
high complexity
ptc CWE-20
4.7
2024-01-10 CVE-2023-29447 Insufficiently Protected Credentials vulnerability in PTC products
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.
high complexity
ptc CWE-522
5.3
2024-01-10 CVE-2023-29444 Uncontrolled Search Path Element vulnerability in PTC products
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.
local
low complexity
ptc CWE-427
7.3
2023-11-30 CVE-2023-5908 Classic Buffer Overflow vulnerability in multiple products
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
network
low complexity
ptc softwaretoolbox ge rockwellautomation CWE-120
critical
9.1
2023-11-30 CVE-2023-5909 Improper Certificate Validation vulnerability in multiple products
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
7.5
2023-06-07 CVE-2023-24476 Unspecified vulnerability in PTC Vuforia Studio
An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.
local
low complexity
ptc
3.3
2023-06-07 CVE-2023-27881 Unspecified vulnerability in PTC Vuforia Studio
A user could use the “Upload Resource” functionality to upload files to any location on the disk.
network
low complexity
ptc
critical
9.9
2023-06-07 CVE-2023-29152 Unspecified vulnerability in PTC Vuforia Studio
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
network
low complexity
ptc
8.1