Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.
2022-03-16T15:15:16.343
2024-11-21T06:51:52.383
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ptc | axeda_agent | < 6.9.1 | Yes |
| Application | ptc | axeda_desktop_server | < 6.9.215 | Yes |