Impact
A critical access‑control bypass has been identified in PTC Windchill Risk and Reliability Enterprise Edition. The flaw permits an attacker to gain unauthorized access to protected functions or data that should be restricted. The weakness is consistent with missing authentication checks for sensitive functions (CWE‑306) and the accidental exposure of security credentials (CWE‑620), potentially allowing the attacker to retrieve or modify confidential risk data.
Affected Systems
Windchill Risk and Reliability Enterprise Edition (formerly Relex) – PTC. The CVE does not specify impacted revisions or patch levels. Administrators should verify whether their installations are on the susceptible version series.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical, and the absence of an EPSS score means current exploitation likelihood is unknown but should be treated as high. The vulnerability is listed outside of the CISA KEV catalog. Likely exploitation would occur via remote web interfaces where the application is exposed, and would require no special privileges beyond an unauthenticated or low‑privilege attacker.
OpenCVE Enrichment