PT-2024-28827 · Ptc · Ptc Thingworx

Abdulazeiz Rashed Aldhanhani

·

Published

2024-08-27

·

Updated

2024-08-30

·

CVE-2024-40395

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PTC ThingWorx version 9.5.0
Description An Insecure Direct Object Reference (IDOR) in PTC ThingWorx allows attackers to view sensitive information, including personally identifiable information (PII), regardless of access level.
Recommendations For PTC ThingWorx version 9.5.0, consider restricting access to sensitive information as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-40395

Affected Products

Ptc Thingworx