The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGe Digital Industrial Gateway Server
APPGe≤ 7.612Ptc Kepware Server
APPPtc≤ 6.12Ptc Kepware Serverex
APPPtc≤ 6.12Ptc Thingworx Edge C Sdk
APPPtc≤ 2.2.12.1052Ptc Thingworx Edge Microserver
APPPtc≤ 5.4.10.0Ptc Thingworx Industrial Connectivity
APPPtcall versionsPtc Thingworx Kepware Edge
APPPtc≤ 1.5Ptc Thingworx .net Sdk
APPPtc≤ 5.8.4.971Rockwellautomation Kepserver Enterprise
APPRockwellautomation≤ 6.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2023-5908CRITICAL9.1PL ✓same product
Buffer overflow w KEPServerEX umożliwiający crash lub wyciek danych
CVE-2022-2848CRITICAL9.1PL ✓same product
Zdalne wykonanie kodu w Kepware KEPServerEX – heap buffer overflow
CVE-2022-2825CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w Kepware KEPServerEX — stack-based buffer overflow
CVE-2023-0755CRITICAL9.8PL ✓same product
Nieprawidłowa walidacja indeksu tablicy w produktach GE/PTC — RCE
CVE-2020-27267CRITICAL9.1PL ✓same product
Heap-based buffer overflow w KEPServerEX i powiązanych produktach OPC UA