CRITICAL🇵🇱 Wersja polska

CVE-2023-5908

CVSS 9.1v3.1pub. 2023-11-30upd. 2024-11-21

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

🤖 AI Analysis
How it works

The vulnerability results from a buffer overflow error (CWE-122: heap-based buffer overflow, CWE-120: classic buffer overflow). An attacker can send specially crafted data to the vulnerable product over the network without requiring any privileges or user interaction. This can result in memory corruption, leading to process failure or memory content disclosure.

Impact

An attacker can cause product unavailability (crash/DoS) or gain access to sensitive information stored in process memory. Both scenarios can seriously disrupt industrial environments (OT/ICS).

Mitigation & patch

Patches available from the vendor should be applied according to the references — detailed information about patched versions is available in the CISA ICS advisory ICSA-23-334-03 at https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03

Who is affected

GE Industrial Gateway Server, PTC KEPServerEX, PTC OPC-Aggregator, PTC ThingWorx Industrial Connectivity, PTC ThingWorx Kepware Edge — versions indicated in vendor references (CISA ICS advisory ICSA-23-334-03)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Ge Industrial Gateway Server

    APP
    Ge
    ≤ 7.614
  • Ptc Keepserverex

    APP
    Ptc
    ≤ 6.14.263.0
  • Ptc Opc Aggregator

    APP
    Ptc
    ≤ 6.14
  • Ptc Thingworx Industrial Connectivity

    APP
    Ptc
    all versions
  • Ptc Thingworx Kepware Edge

    APP
    Ptc
    ≤ 1.7
  • Ptc Thingworx Kepware Server

    APP
    Ptc
    ≤ 6.14.263.0
  • Rockwellautomation Kepserver Enterprise

    APP
    Rockwellautomation
    ≤ 6.14.263.0
  • Softwaretoolbox Top Server

    APP
    Softwaretoolbox
    ≤ 6.14.263.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2022-2825CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w Kepware KEPServerEX — stack-based buffer overflow

CVE-2022-2848CRITICAL9.1PL ✓same product

Zdalne wykonanie kodu w Kepware KEPServerEX – heap buffer overflow

CVE-2023-0755CRITICAL9.8PL ✓same product

Nieprawidłowa walidacja indeksu tablicy w produktach GE/PTC — RCE

CVE-2023-0754CRITICAL9.8PL ✓same product

Integer overflow umożliwiający RCE w produktach GE Digital i PTC Kepware

CVE-2020-27265CRITICAL9.8PL ✓same product

Stack-based buffer overflow w KEPServerEX i powiązanych produktach OPC UA