Improper validation of certificate with host mismatch in PTC products - CVE-2023-5909

 

Improper validation of certificate with host mismatch in PTC products - CVE-2023-5909

Published: December 4, 2023


Vulnerability identifier: #VU83637
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5909
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected application does not properly validate certificates from clients. A remote attacker can connect to the application and gain access to sensitive information.


Affected software

Kepware KepServerEX
ThingWorx Kepware Server
ThingWorx Industrial Connectivity
ThingWorx Kepware Edge
OPC Aggregator
KEPServer Enterprise
Industrial Gateway Server
TOP Server

How to mitigate CVE-2023-5909

Install updates from vendor's website.

Kepware KepServerEX - update to 6.15
ThingWorx Kepware Server - update to 6.15
ThingWorx Kepware Edge - update to 1.8
OPC Aggregator - update to 6.15

External References

Related Security Bulletins