PTC License Server Bug Needs Immediate Patch Against Critical Flaw

Share This Post

Days after the Cybersecurity and Infrastructure Security Agency (CISA) and industrial computer-aided design software provider PTC raised the alarm about a critical flaw in one of its servers, a patch has been issued.

First reported on June 25, the critical industrial control systems flaw in one of the engineering and manufacturing software provider’s servers, tracked under CVE-2024-6071, left systems exposed to the Internet and vulnerable to unauthorized remote access. The flaw was assigned the highest CVSS score of 10. Affected Creo Elements/Direct License Servers are advised to update immediately.

PTC noted there is no evidence the flaw has been exploited in the wild. The vulnerability does not impact the PTC Creo License Server, the vendor said.

PTC is used in industrial engineering and manufacturing organizations worldwide by brands like Volvo, Lufthansa, Medtronic, HP, Merck, and GE.

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdf3e8974884e46be/6684430c0226d91a3fa4ce39/industrial_modeling_Ragma_Images_Alamy.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.