KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
The vulnerability results from a buffer overflow error (CWE-122: heap-based buffer overflow, CWE-120: classic buffer overflow). An attacker can send specially crafted data to the vulnerable product over the network without requiring any privileges or user interaction. This can result in memory corruption, leading to process failure or memory content disclosure.
An attacker can cause product unavailability (crash/DoS) or gain access to sensitive information stored in process memory. Both scenarios can seriously disrupt industrial environments (OT/ICS).
Patches available from the vendor should be applied according to the references — detailed information about patched versions is available in the CISA ICS advisory ICSA-23-334-03 at https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03
GE Industrial Gateway Server, PTC KEPServerEX, PTC OPC-Aggregator, PTC ThingWorx Industrial Connectivity, PTC ThingWorx Kepware Edge — versions indicated in vendor references (CISA ICS advisory ICSA-23-334-03)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HGe Industrial Gateway Server
APPGe≤ 7.614Ptc Keepserverex
APPPtc≤ 6.14.263.0Ptc Opc Aggregator
APPPtc≤ 6.14Ptc Thingworx Industrial Connectivity
APPPtcall versionsPtc Thingworx Kepware Edge
APPPtc≤ 1.7Ptc Thingworx Kepware Server
APPPtc≤ 6.14.263.0Rockwellautomation Kepserver Enterprise
APPRockwellautomation≤ 6.14.263.0Softwaretoolbox Top Server
APPSoftwaretoolbox≤ 6.14.263.0
Related vulnerabilities
RCE bez uwierzytelnienia w Kepware KEPServerEX — stack-based buffer overflow
Zdalne wykonanie kodu w Kepware KEPServerEX – heap buffer overflow
Nieprawidłowa walidacja indeksu tablicy w produktach GE/PTC — RCE
Integer overflow umożliwiający RCE w produktach GE Digital i PTC Kepware
Stack-based buffer overflow w KEPServerEX i powiązanych produktach OPC UA