PTC Creo Elements/Direct License Server Missing Authorization
Published Jun 27, 2024
10.0
CRITICALCVSS 4.0
EPSS 1.12%
Description
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
Affected products
-
- Version 0StatusaffectedConstraints<=20.7.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| PTC | Creo Elements/Direct License | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<=20.7.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Creo | Creo Elements\/direct License | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
PTC recommends that users upgrade to Creo Elements/Direct License Server 20.7.0.1 or higher version:
* Creo Elements/Direct Drafting https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Model/Drawing Mgr https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Modeling https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct WorkManager https://support.ptc.com/appserver/auth/it/esd/product.jsp
If additional questions remain, please contact PTC Technical Support. https://support.ptc.com/apps/case_logger_viewer/cs/auth/ssl/log
For more information, see PTC's CS article https://www.ptc.com/en/support/article/CS417607 .
References (3)
Change history (0)
No recorded changes yet.