← Back to browse · API

CVE-2022-25251

Severity
CRITICAL
CVSS
9.8
EPSS
0.01871
Risk score
39.85
CISA KEV
No
PoC
No
Published
2022-03-16
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-29948, GHSA-V435-3JG8-VQ2R
Products
PTC:Axeda Desktop Server for Windows All Versions, PTC:Axeda agent All Versions
Sources
euvd EUVD-2022-29948

Description

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration.

References