VulnerabilityModified
CVE-2023-0755
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
CRITICAL 9.8EPSS 11.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.78% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-129
- Affected
- ge/digital industrial gateway server · ptc/kepware server · ptc/kepware serverex · ptc/thingworx .net-sdk · ptc/thingworx edge c-sdk · ptc/thingworx edge microserver · ptc/thingworx industrial connectivity · ptc/thingworx kepware edge · rockwellautomation/kepserver enterprise
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-054-01Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-054-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.