QID 591239
QID 591239: PTC Kepware KEPServerEX (Update A) Multiple Vulnerabilities (ICSA-22-242-10)
AFFECTED PRODUCTS
The following products are affected by the vulnerabilities found in Kepware KEPServerEX, a connectivity platform:
Kepware KEPServerEX: Versions prior to v6.12
ThingWorkx Kepware Server: Versions prior to v6.12
OPC-Aggregator: Versions prior to v6.12
GE Digital Industrial Gateway Server: Versions prior to v7.612
Software Toolbox TOP Server: Versions prior to v6.12
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using registry in "HKLM\Software
Specifically crafted OPC UA messages transmitted to the server could allow an attacker to crash the server and leak data and crash the server and remotely execute code.
Customers are advised to refer to CERT MITIGATIONS section ICSA-22-242-10 for affected packages and patching details.
- ICSA-22-242-10 -
www.cisa.gov/uscert/ics/advisories/icsa-22-242-10
CVEs related to QID 591239
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-22-242-10 |
|