« Volver al listado

CVE-2023-5908

Estado: ModificadaCrítica (9.1)—

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5908",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "PTC",
          "product": "KEPServerEX",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Kepware Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Industrial Connectivity",
          "versions": [
            {
              "status": "affected",
              "version": "All versions"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "OPC-Aggregator",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Kepware Edge",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.7"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Rockwell Automation ",
          "product": "KEPServer Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "GE Gigital",
          "product": "Industrial Gateway Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "7.614"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Software Toolbox",
          "product": "TOP Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-30T22:15:09.923",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\n\n\nKEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "KEPServerEX es vulnerable a un desbordamiento del búfer que puede permitir que un atacante bloquee el producto al que se accede o filtre información."
    }
  ],
  "lastModified": "2026-06-17T06:49:38.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ge:industrial_gateway_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAC36939-C47F-4426-A684-0252C014CB05",
              "versionEndIncluding": "7.614"
            },
            {
              "criteria": "cpe:2.3:a:ptc:keepserverex:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C003AF3-3140-4AD9-8407-D3C216D72AA0",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:ptc:opc-aggregator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0A4FE5D-D1DD-4854-B709-3E0A54D6BE97",
              "versionEndIncluding": "6.14"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_industrial_connectivity:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D01A814D-8F2B-4B88-A66B-F2A2C293A6AB"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8B99ED4-CEB0-463D-9900-426C6108A009",
              "versionEndIncluding": "1.7"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14930935-3DE4-403F-9F6A-9E4490C3B95D",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40663AD6-24DE-4D75-AA95-0D4E6A2ADF04",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:softwaretoolbox:top_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB7C7A8B-38A0-4A48-B78A-F5FAA2A9E20F",
              "versionEndIncluding": "6.14.263.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}