Heap-based buffer overflow in PTC products - CVE-2023-5908
Published: December 4, 2023
Vulnerability identifier: #VU83635
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5908
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a boundary error. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack or leak information.
Affected software
Kepware KepServerEX
ThingWorx Kepware Server
ThingWorx Industrial Connectivity
ThingWorx Kepware Edge
OPC Aggregator
KEPServer Enterprise
Industrial Gateway Server
TOP Server
ThingWorx Kepware Server
ThingWorx Industrial Connectivity
ThingWorx Kepware Edge
OPC Aggregator
KEPServer Enterprise
Industrial Gateway Server
TOP Server
How to mitigate CVE-2023-5908
Install updates from vendor's website.
Kepware KepServerEX - update to 6.15
ThingWorx Kepware Server - update to 6.15
ThingWorx Kepware Edge - update to 1.8
OPC Aggregator - update to 6.15
ThingWorx Kepware Server - update to 6.15
ThingWorx Kepware Edge - update to 1.8
OPC Aggregator - update to 6.15