← Back to browse · API

CVE-2024-6071

Severity
CRITICAL
CVSS
10.0
EPSS
0.01118
Risk score
40.39
CISA KEV
No
PoC
No
Published
2024-06-27
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-47229, GHSA-CM55-W5WP-4FGQ
Products
PTC:Creo Elements/Direct License 0 ≤20.7.0.0
Sources
euvd EUVD-2024-47229

Description

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

References