CVE-2023-0755: Out-of-bounds Read
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0755?
CVE-2023-0755 is a vulnerability that affects Ge Digital Industrial Gateway Server, Ptc Kepware Server, Ptc Kepware Serverex, Ptc Thingworx .net-sdk, Ptc Thingworx Edge C-sdk, Ptc Thingworx Edge Microserver, Ptc Thingworx Industrial Connectivity, Ptc Thingworx Kepware Edge, and Rockwellautomation Kepserver Enterprise. It allows an attacker to crash the server and remotely execute arbitrary code.
How severe is CVE-2023-0755?
CVE-2023-0755 has a severity rating of 9.8 (critical).
How can an attacker exploit CVE-2023-0755?
An attacker can exploit CVE-2023-0755 by sending specially crafted input to trigger an improper validation of array index, causing the server to crash and potentially execute arbitrary code.
What is the affected version of Ge Digital Industrial Gateway Server in CVE-2023-0755?
The affected version of Ge Digital Industrial Gateway Server in CVE-2023-0755 is up to and including version 7.612.
How can I mitigate the vulnerability in CVE-2023-0755?
To mitigate the vulnerability in CVE-2023-0755, it is recommended to apply the necessary security patches or updates provided by the vendor and follow their recommended mitigation steps.