CVE-2023-0755

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
gedigital_industrial_gateway_server
𝑥
≤ 7.612
ptckepware_server
𝑥
≤ 6.12
ptckepware_serverex
𝑥
≤ 6.12
ptcthingworx_.net-sdk
𝑥
≤ 5.8.4.971
ptcthingworx_edge_c-sdk
𝑥
≤ 2.2.12.1052
ptcthingworx_edge_microserver
𝑥
≤ 5.4.10.0
ptcthingworx_industrial_connectivity
-
ptcthingworx_kepware_edge
𝑥
≤ 1.5
rockwellautomationkepserver_enterprise
𝑥
≤ 6.12
𝑥
= Vulnerable software versions