Vulnerabilities > PTC > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-40395 Authorization Bypass Through User-Controlled Key vulnerability in PTC Thingworx 9.5.0
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
network
low complexity
ptc CWE-639
6.5
2024-01-10 CVE-2023-29446 Improper Input Validation vulnerability in PTC products
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file.
local
high complexity
ptc CWE-20
4.7
2024-01-10 CVE-2023-29447 Insufficiently Protected Credentials vulnerability in PTC products
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.
high complexity
ptc CWE-522
5.3
2023-06-07 CVE-2023-29502 Path Traversal vulnerability in PTC Vuforia Studio
Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.
network
low complexity
ptc CWE-22
4.3
2022-03-16 CVE-2022-25248 Information Exposure vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service.
network
low complexity
ptc CWE-200
5.0
2022-03-16 CVE-2022-25249 Path Traversal vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server..
network
low complexity
ptc CWE-22
5.0
2022-03-16 CVE-2022-25250 Missing Authentication for Critical Function vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication.
network
low complexity
ptc CWE-306
5.0
2022-03-16 CVE-2022-25252 Improper Check for Unusual or Exceptional Conditions vulnerability in PTC Axeda Agent and Axeda Desktop Server
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception.
network
low complexity
ptc CWE-754
5.0
2021-01-14 CVE-2020-27267 Out-of-bounds Write vulnerability in multiple products
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow.
6.4
2021-01-14 CVE-2020-27263 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow.
6.4