Known vulnerabilities in ThingWorx Kepware Server

Vendor: PTC
Software CPE: cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ThingWorx Kepware Server ThingWorx Kepware Server is affected by 8 known vulnerabilities: 3 high, 3 medium, 2 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83637 - Improper Validation of Certificate with Host Mismatch
CVE-2023-5909
CWE-297 Medium
No
No
6.15 04.12.2023 SB2023120409
SB2023120510
SB2023120512
and 1 more
#VU83635 - Heap-based Buffer Overflow
CVE-2023-5908
CWE-122 High
No
No
6.15 04.12.2023 SB2023120409
SB2023120510
SB2023120512
and 1 more
#VU80226 - Insufficiently Protected Credentials
CVE-2023-29447
CWE-522 Medium
No
No
- 01.09.2023 SB2023090139
#VU80225 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-29446
CWE-22 Medium
No
No
- 01.09.2023 SB2023090139
#VU80224 - Uncontrolled Search Path Element
CVE-2023-29445
CWE-427 Low
No
No
- 01.09.2023 SB2023090139
#VU80223 - Uncontrolled Search Path Element
CVE-2023-29444
CWE-427 Low
No
No
- 01.09.2023 SB2023090139
#VU72579 - Integer overflow
CVE-2023-0754
CWE-190 High
No
No
6.13 27.02.2023 SB2023022709
SB2023022710
SB2023022712
and 1 more
#VU72578 - Improper Validation of Array Index
CVE-2023-0755
CWE-129 High
No
No
6.13 27.02.2023 SB2023022709
SB2023022710
SB2023022712
and 1 more