CVE-2023-5909









KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.







ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
geindustrial_gateway_server
𝑥
≤ 7.614
ptckeepserverex
𝑥
≤ 6.14.263.0
ptcopc-aggregator
𝑥
≤ 6.14
ptcthingworx_industrial_connectivity
-
ptcthingworx_kepware_edge
𝑥
≤ 1.7
ptcthingworx_kepware_server
𝑥
≤ 6.14.263.0
rockwellautomationkepserver_enterprise
𝑥
≤ 6.14.263.0
softwaretoolboxtop_server
𝑥
≤ 6.14.263.0
𝑥
= Vulnerable software versions