CVE-2024-6071: Creo Elements\/direct License

Critical severity, CVSS 10.0. EPSS: 1.1% chance of exploitation in the next 30 days.

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

Affected products

  • Creo Creo Elements\/direct License: up to and including 20.7.0.0
  • PTC Creo Elements/direct License: up to and including 20.7.0.0

Published 2024-06-27. Last modified 2026-06-17.