CVE-2023-0755

EUVD-2023-12773
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
gedigital_industrial_gateway_server
𝑥
≤ 7.612
ptckepware_server
𝑥
≤ 6.12
ptckepware_serverex
𝑥
≤ 6.12
ptcthingworx_.net-sdk
𝑥
≤ 5.8.4.971
ptcthingworx_edge_c-sdk
𝑥
≤ 2.2.12.1052
ptcthingworx_edge_microserver
𝑥
≤ 5.4.10.0
ptcthingworx_industrial_connectivity
-
ptcthingworx_kepware_edge
𝑥
≤ 1.5
rockwellautomationkepserver_enterprise
𝑥
≤ 6.12
𝑥
= Vulnerable software versions