Vulnerabilities > PTC

DATE CVE VULNERABILITY TITLE RISK
2022-03-16 CVE-2022-25250 Missing Authentication for Critical Function vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication.
network
low complexity
ptc CWE-306
5.0
2022-03-16 CVE-2022-25251 Missing Authentication for Critical Function vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication.
network
low complexity
ptc CWE-306
7.5
2022-03-16 CVE-2022-25252 Improper Check for Unusual or Exceptional Conditions vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception.
network
low complexity
ptc CWE-754
5.0
2021-01-14 CVE-2020-27267 Out-of-bounds Write vulnerability in multiple products
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow.
6.4
2021-01-14 CVE-2020-27265 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow.
7.5
2021-01-14 CVE-2020-27263 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow.
6.4
2018-12-17 CVE-2018-20092 Path Traversal vulnerability in PTC Thingworx Platform
PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.
network
low complexity
ptc CWE-22
5.0
2018-10-01 CVE-2018-17218 Cross-site Scripting vulnerability in PTC Thingworx Platform
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2.
network
ptc CWE-79
3.5
2018-10-01 CVE-2018-17217 Use of Hard-coded Credentials vulnerability in PTC Thingworx Platform
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2.
network
low complexity
ptc CWE-798
5.0
2018-10-01 CVE-2018-17216 Information Exposure vulnerability in PTC Thingworx Platform
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2.
network
low complexity
ptc CWE-200
4.0