CVE-2023-0754
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
23/02/2023
Last modified:
07/11/2023
Description
<br />
The affected products are vulnerable to an integer<br />
overflow or wraparound, which could allow an attacker to crash the server and remotely<br />
execute arbitrary code.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ge:digital_industrial_gateway_server:*:*:*:*:*:*:*:* | 7.612 (including) | |
| cpe:2.3:a:ptc:kepware_server:*:*:*:*:*:*:*:* | 6.12 (including) | |
| cpe:2.3:a:ptc:kepware_serverex:*:*:*:*:*:*:*:* | 6.12 (including) | |
| cpe:2.3:a:ptc:thingworx_.net-sdk:*:*:*:*:*:*:*:* | 5.8.4.971 (including) | |
| cpe:2.3:a:ptc:thingworx_edge_c-sdk:*:*:*:*:*:*:*:* | 2.2.12.1052 (including) | |
| cpe:2.3:a:ptc:thingworx_edge_microserver:*:*:*:*:*:*:*:* | 5.4.10.0 (including) | |
| cpe:2.3:a:ptc:thingworx_industrial_connectivity:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:* | 1.5 (including) | |
| cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:* | 6.12 (including) |
To consult the complete list of CPE names with products and versions, see this page



