Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
criticalDetails
Affiliates of the Cl0p ransomware group are actively exploiting a vulnerability chain in PTC products. Attackers combine a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution.
Affected Systems
Internet-exposed PTC Windchill and FlexPLM deployments.
Potential Impact
Data extortion and theft of sensitive intellectual property, followed by potential ransomware deployment across the network.
Mitigations
Monitor vendor advisories for patches and guidance.