PT-2022-1805 · Ptc · Axeda Desktop Server For Windows+1

Published

2022-03-07

·

Updated

2022-03-28

·

CVE-2022-25246

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axeda agent (All versions) Axeda Desktop Server for Windows (All versions)
Description The issue is related to the use of hard-coded credentials for the UltraVNC installation in the affected software. This could allow a remote authenticated attacker to gain full remote control of the host operating system.
Recommendations For Axeda agent (All versions), consider disabling the UltraVNC installation until a patch is available. For Axeda Desktop Server for Windows (All versions), restrict access to the UltraVNC installation to minimize the risk of exploitation. As a temporary workaround, avoid using the hard-coded credentials in the UltraVNC installation until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01216
CVE-2022-25246

Affected Products

Axeda Desktop Server For Windows
Axeda Agent