Back

CRITICAL

PTC Creo Elements/Direct License Server Missing Authorization

Published Jun 27, 2024

Description

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

Affected products

Remediation

Vendor solution

PTC recommends that users upgrade to Creo Elements/Direct License Server 20.7.0.1 or higher version:

* Creo Elements/Direct Drafting https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Model/Drawing Mgr https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Modeling https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct WorkManager https://support.ptc.com/appserver/auth/it/esd/product.jsp

If additional questions remain, please contact PTC Technical Support. https://support.ptc.com/apps/case_logger_viewer/cs/auth/ssl/log

For more information, see PTC's CS article https://www.ptc.com/en/support/article/CS417607 .

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jun 27, 2024
Updated Aug 1, 2024
Reserved Jun 17, 2024
CISA Vulnrichment
Updated Jun 28, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Jun 27, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-47229