CVE-2023-0755
critical · 9.8The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
9.8
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2023-02-23
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-129
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ge | digital_industrial_gateway_server | <= 7.612 |
| ptc | kepware_server | <= 6.12 |
| ptc | kepware_serverex | <= 6.12 |
| ptc | thingworx_.net-sdk | <= 5.8.4.971 |
| ptc | thingworx_edge_c-sdk | <= 2.2.12.1052 |
| ptc | thingworx_edge_microserver | <= 5.4.10.0 |
| ptc | thingworx_industrial_connectivity | all versions |
| ptc | thingworx_kepware_edge | <= 1.5 |
| rockwellautomation | kepserver_enterprise | <= 6.12 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-0755