CVE-2024-40395

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
References
Link Resource
https://pastebin.com/9dc4LYGA Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ptc:thingworx:9.5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-27 16:15

Updated : 2025-03-25 17:15


NVD link : CVE-2024-40395

Mitre link : CVE-2024-40395

CVE.ORG link : CVE-2024-40395


JSON object : View

Products Affected

ptc

  • thingworx
CWE
CWE-639

Authorization Bypass Through User-Controlled Key