CVE-2022-25252
Summary
| CVE | CVE-2022-25252 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-16 15:15:00 UTC |
| Updated | 2022-03-28 13:32:00 UTC |
| Description | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to crash the affected product. |
Risk And Classification
Problem Types: CWE-754
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ptc | Axeda Agent | All | All | All | All |
| Application | Ptc | Axeda Desktop Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CS363561 - Security vulnerabilities identified in the Axeda agent and Axeda Desktop Server | MISC | www.ptc.com | |
| PTC Axeda agent and Axeda Desktop Server (Update B) | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yuval Shoshani and Elad Luz of CyberMDX and Vedere Labs reported these vulnerabilities to PTC
There are currently no legacy QID mappings associated with this CVE.