Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.
2022-03-16T15:15:16.343
2024-11-21T06:51:52.383
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ptc | axeda_agent | < 6.9.1 | Yes |
Application | ptc | axeda_desktop_server | < 6.9.215 | Yes |