PatchSiren cyber security CVE debrief
CVE-2024-6071 PTC CVE debrief
PTC Creo Elements/Direct License Server contains a critical unauthenticated remote code execution vulnerability. The license server's web interface allows unauthenticated remote attackers to execute arbitrary operating system commands on the server, resulting in complete system compromise. This vulnerability affects multiple products in the Creo Elements/Direct product family that rely on the affected license server component. CISA published the initial advisory on June 25, 2024, with an update on July 2, 2024 expanding the list of affected products.
- Vendor
- PTC
- Product
- Creo Elements/Direct Drafting
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-25
- Original CVE updated
- 2024-07-02
- Advisory published
- 2024-06-25
- Advisory updated
- 2024-07-02
Who should care
Organizations running PTC Creo Elements/Direct product suites in engineering, manufacturing, and industrial design environments. Critical infrastructure operators using these CAD/CAM/CAE tools for product development. License server administrators and OT security teams responsible for protecting engineering workstation environments.
Technical summary
The Creo Elements/Direct License Server (MEls) exposes a web management interface that fails to properly authenticate or sanitize user input, allowing unauthenticated remote attackers to inject and execute arbitrary operating system commands. The vulnerability is exploitable over the network without authentication, with low attack complexity. Successful exploitation grants attackers full control over the license server host with potential lateral movement into connected engineering workstations and product data management systems. Affected versions include Creo Elements/Direct License Server 20.7.0.0 and earlier, with the fix available in version 20.7.0.1. Multiple dependent products are affected including Drafting, Model Manager/Drawing Manager, Modeling, and WorkManager/DDM across versions 15.00 through 20.7 (20.4 for WorkManager/DDM).
Defensive priority
CRITICAL
Recommended defensive actions
- Upgrade Creo Elements/Direct License Server to version 20.7.0.1 or higher immediately
- Apply vendor fixes for affected Creo Elements/Direct product components
- Contact PTC Technical Support for additional assistance if needed
- Review PTC customer support article CS417607 for detailed guidance
- Restrict network access to the license server web interface to authorized administrative hosts only
- Monitor license server systems for indicators of compromise
Evidence notes
Vulnerability description and affected product versions are derived from CISA CSAF advisory ICSA-24-177-02. CVSS 3.1 score of 10.0 reflects network attack vector, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability with scope change.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6071 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6071
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6071 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6071
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-177-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-177-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.