APP: Axeda agent CVE-2022-25247 Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Axeda agent. A successful attack can lead to arbitrary code execution.

Extended Description

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code execution.

Affected Products

Ptc axeda_desktop_server

References

CVE: CVE-2022-25247

Short Name
APP:MISC:AXEDA-AGENT-RCE
Severity
Major
Recommended
True
Recommended Action
None
Category
APP
Keywords
Axeda CVE-2022-25247 Code Execution Remote agent
Release Date
03/24/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
Port
TCP/3076
False Positive
Unknown
Vendors

Ptc

CVSS Score

10.0

Found a potential security threat?