CVE-2023-5909: Improper Validation of Certificate with Host Mismatch in PTC KEPServerEx
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-5909?
CVE-2023-5909 is a vulnerability in PTC KEPServerEx that allows unauthenticated users to connect due to improper validation of certificates.
What is the severity of CVE-2023-5909?
CVE-2023-5909 has a severity rating of 7.5 (high).
Which software is affected by CVE-2023-5909?
CVE-2023-5909 affects GE Industrial Gateway Server, PTC KEPServerEx, PTC OPC-Aggregator, PTC ThingWorx Industrial Connectivity, PTC ThingWorx Kepware Edge, PTC ThingWorx Kepware Server, RockwellAutomation KepServer Enterprise, and Softwaretoolbox Top Server.
How can unauthenticated users connect due to CVE-2023-5909?
Unauthenticated users can connect due to CVE-2023-5909 because KEPServerEx does not properly validate certificates from clients.
Is there a reference for CVE-2023-5909?
Yes, you can find more information about CVE-2023-5909 at this link: https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03