PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
Fixes

Solution

PTC recommends that users upgrade to Creo Elements/Direct License Server 20.7.0.1 or higher version: * Creo Elements/Direct Drafting https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Model/Drawing Mgr https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct Modeling https://support.ptc.com/appserver/auth/it/esd/product.jsp * Creo Elements/Direct WorkManager https://support.ptc.com/appserver/auth/it/esd/product.jsp If additional questions remain, please contact PTC Technical Support. https://support.ptc.com/apps/case_logger_viewer/cs/auth/ssl/log For more information, see PTC's CS article https://www.ptc.com/en/support/article/CS417607 .


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-01T21:25:03.240Z

Reserved: 2024-06-17T15:17:28.397Z

Link: CVE-2024-6071

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.240Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-27T23:15:50.470

Modified: 2024-11-21T09:48:53.803

Link: CVE-2024-6071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.