QID 591214

QID 591214: PTC Products Multiple Vulnerabilities (ICSA-22-242-10)

This updated advisory is a follow-up to the original advisory titled ICSA-22-242-10 PTC Kepware KEPServerEX that was published August 30, 2022

The following PTC products are affected by vulnerabilities found in Kepware KEPServerEX, a connectivity platform
Kepware KEPServerEX: Versions prior to 6.12
ThingWorkx Kepware Server: Versions prior to 6.12
ThingWorkx Industrial Connectivity: All versions
OPC-Aggregator: Versions prior to 6.12
ThingWorkx Kepware Edge: Versions 1.4 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version

Successful exploitation of these vulnerabilities could allow an attacker to crash the device or remotely execute arbitrary code.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-242-10 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591214

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-242-10 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-242-10