QID 591429

Date Published: 2024-03-05

QID 591429: PTC KEPServerEX Multiple Vulnerabilities (ICSA-23-334-03)

CVE-2023-5908,CVE-2023-5909 - Vulnerabilities: Heap-based Buffer Overflow, Improper Validation of Certificate with Host Mismatch.

AFFECTED PRODUCTS
The following products are affected by the vulnerabilities found in Kepware KEPServerEX, a connectivity platform:
KEPServerEX: v6.14.263.0 and prior
ThingWorx Kepware Server: v6.14.263.0 and prior
ThingWorx Industrial Connectivity: All versions
OPC-Aggregator: v6.14 and prior
Software Toolbox TOP Server: Versions v6.14.263.0 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using registry entry of related services.

Successful exploitation of these vulnerabilities could lead to a server crashing, a denial-of-service condition, data leakage, or remote code execution.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-23-334-03 for affected packages and patching details.

    CVEs related to QID 591429

    Software Advisories
    Advisory ID Software Component Link
    CSA-23-334-03 URL Logo www.cisa.gov/news-events/ics-advisories/icsa-23-334-03