A set of seven vulnerabilities, known as Access:7 , have been found in PTC 's Axeda , a solution used to remotely access and manage more than 150 connected devices from more than 100 vendors.

See also: CISA to organizations: Fix 95 actively exploited vulnerabilities
Three of the security issues received a severity rating of at least 9.4 and could be used for remote code execution on devices running a vulnerable version of the Axeda agent.
The Axeda platform, developed by Parametric Technology Corporation (PTC), aims to provide data from IoT devices on the network and the option for remote servicing.
Axeda users can operate on a wide variety of connected systems, with devices in the healthcare industry being most prevalent, making them attractive targets for attacks.
As security researchers at Forescout 's Vedere Labs and CyberMDX discovered , all Axeda versions older than 6.9.3 are vulnerable to a set of seven security flaws.
The impact of Access:7 issues ranges from information disclosure and denial of service (DoS) to remote code execution.
The Axeda platform provides connected device manufacturers with a development kit that allows them to “create a configured agent installation for a range of products,” says Forescout.
See also: Vulnerability found in WordPress plugin with over 3 million installations
In this way, manufacturers receive telemetry data and devices can receive services remotely. Each user can represent one or more devices, depending on where they are located: if placed in a gateway, they can serve multiple products or elements, behind the gateway.

It's worth noting that PTC has phased out Axeda in favor of a different, more flexible platform called ThingWorx. However, Axeda is still used by customers in a variety of industries.
Anonymized customer data collected by Forescout through its Device Cloud solution shows more than 2,000 unique devices running Axeda on their networks.
According to a report by Forescout, in the case of medical devices, even less severe Access:7 vulnerabilities can have a significant impact.
For example, an attacker who gains read access by exploiting the CVE–2022-25249 in an imaging or laboratory device could steal protected health information (PHI) or diagnostic data about a patient and sell it for profit if it is a high-value victim.
Similarly, exploiting a bug like CVE-2022-25250could shut down Axeda on a device, making remote servicing impossible. This could lead to the healthcare facility stopping treatment or a patient’s diagnosis.
See also: T2 Mac security vulnerability allows cracking of passwords!
With a critical vulnerability like CVE-2022-25246, Forescout highlights that the password “for a VNC connection is the same across all models or model families for a vendor.”
Axeda has addressed all of the Access:7 vulnerabilities, and device manufacturers should push their fixes to customers, as patching is the only way to fully mitigate the issues.
