CVE-2023-0755

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/02/2023
Last modified:
07/11/2023

Description

<br /> The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ge:digital_industrial_gateway_server:*:*:*:*:*:*:*:* 7.612 (including)
cpe:2.3:a:ptc:kepware_server:*:*:*:*:*:*:*:* 6.12 (including)
cpe:2.3:a:ptc:kepware_serverex:*:*:*:*:*:*:*:* 6.12 (including)
cpe:2.3:a:ptc:thingworx_.net-sdk:*:*:*:*:*:*:*:* 5.8.4.971 (including)
cpe:2.3:a:ptc:thingworx_edge_c-sdk:*:*:*:*:*:*:*:* 2.2.12.1052 (including)
cpe:2.3:a:ptc:thingworx_edge_microserver:*:*:*:*:*:*:*:* 5.4.10.0 (including)
cpe:2.3:a:ptc:thingworx_industrial_connectivity:-:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:* 1.5 (including)
cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:* 6.12 (including)


References to Advisories, Solutions, and Tools