« Volver al listado

CVE-2023-5909

Estado: ModificadaAlta (7.5)—

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5909",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5909",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-12-09T05:06:00.963177Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "PTC",
          "product": "KEPServerEX",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Kepware Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Industrial Connectivity",
          "versions": [
            {
              "status": "affected",
              "version": "All versions"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "OPC-Aggregator",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Kepware Edge",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.7"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Rockwell Automation ",
          "product": "KEPServer Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "GE Gigital",
          "product": "Industrial Gateway Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "7.614"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Software Toolbox",
          "product": "TOP Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-30T22:15:10.163",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-297"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\n\n\n\n\n\n\nKEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.\n\n\n\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "KEPServerEX no valida adecuadamente los certificados de los clientes, lo que puede permitir que se conecten usuarios no autenticados."
    }
  ],
  "lastModified": "2026-06-17T06:49:38.273",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ge:industrial_gateway_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAC36939-C47F-4426-A684-0252C014CB05",
              "versionEndIncluding": "7.614"
            },
            {
              "criteria": "cpe:2.3:a:ptc:keepserverex:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C003AF3-3140-4AD9-8407-D3C216D72AA0",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:ptc:opc-aggregator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0A4FE5D-D1DD-4854-B709-3E0A54D6BE97",
              "versionEndIncluding": "6.14"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_industrial_connectivity:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D01A814D-8F2B-4B88-A66B-F2A2C293A6AB"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8B99ED4-CEB0-463D-9900-426C6108A009",
              "versionEndIncluding": "1.7"
            },
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14930935-3DE4-403F-9F6A-9E4490C3B95D",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40663AD6-24DE-4D75-AA95-0D4E6A2ADF04",
              "versionEndIncluding": "6.14.263.0"
            },
            {
              "criteria": "cpe:2.3:a:softwaretoolbox:top_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB7C7A8B-38A0-4A48-B78A-F5FAA2A9E20F",
              "versionEndIncluding": "6.14.263.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}