CVE-2023-5909
30.11.2023, 22:15
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.Enginsight
Vendor | Product | Version |
---|---|---|
ge | industrial_gateway_server | 𝑥 ≤ 7.614 |
ptc | keepserverex | 𝑥 ≤ 6.14.263.0 |
ptc | opc-aggregator | 𝑥 ≤ 6.14 |
ptc | thingworx_industrial_connectivity | - |
ptc | thingworx_kepware_edge | 𝑥 ≤ 1.7 |
ptc | thingworx_kepware_server | 𝑥 ≤ 6.14.263.0 |
rockwellautomation | kepserver_enterprise | 𝑥 ≤ 6.14.263.0 |
softwaretoolbox | top_server | 𝑥 ≤ 6.14.263.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-297 - Improper Validation of Certificate with Host MismatchThe software communicates with a host that provides a certificate, but the software does not properly ensure that the certificate is actually associated with that host.
- CWE-295 - Improper Certificate ValidationThe software does not validate, or incorrectly validates, a certificate.