peter bassill · operator
$ cve CVE-2022-25247 JSON

CVE-2022-25247

9.8
CRITICAL · CVSS 3.1 · EPSS 4.1% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.14% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2022-03-16
Last modified2026-06-17

Affected (2)

VendorProduct
ptcaxeda agent
ptcaxeda desktop server

References

→ the Explorer  ·  watch your stack  ·  NVD