Overview
Researchers have identified 7 vulnerabilities affecting the Axeda IoT framework which is used in more than 150 different models of device. The majority are medical devices but others in the financial sector, manufacturing, and other sectors are also affected.
Vulnerabilities include hard-coded credentials, unauthenticated command API, and full command execution.
Impact
A network-based attacker could remotely execute code, access the file system or alter system configurations on devices built with PTC Axeda.
Vulnerability Detection
These can be difficult to detect and highlights the need for detailed inventory management.
Affected Products
All versions of the Axeda Agent prior to 6.9.3.
A list of devices is available here.
Containment, Mitigations & Remediations
As a supply chain issue, updates for devices will need to be provided by individual manufacturers.
Where possible, IoT devices should not be internet facing and remote access should be controlled using a VPN. Network segmentation can reduce the risk from compromised devices.
The following ports can be blocked to prevent exploitation:












