ICSA-23-334-03: Ptc kepserverex vulnerability
Affected Software
8 affected components
: PTC KEPServerEX: v6.14.263.0 and prior
: PTC ThingWorx Kepware Server: v6.14.263.0 and prior
: PTC ThingWorx Industrial Connectivity
: PTC OPC-Aggregator: v6.14 and prior
: PTC ThingWorx Kepware Edge: v1.7 and prior
: PTC Rockwell Automation KEPServer Enterprise<=6.14.263.0
: PTC GE Digital Industrial Gateway Server<=7.614
: PTC Software Toolbox TOP Server<=6.14.263.0
Event History
Mar 25, 2025
Advisory Published
11:01 AM
Frequently Asked Questions
1
What is the severity of ICSA-23-334-03?
The severity of ICSA-23-334-03 is classified as critical.
2
What is the primary vulnerability addressed in ICSA-23-334-03?
ICSA-23-334-03 addresses a vulnerability related to improper input validation in PTC software.
3
How do I fix ICSA-23-334-03?
To fix ICSA-23-334-03, users should upgrade to the latest versions of the affected PTC products.
4
Which PTC products are impacted by ICSA-23-334-03?
ICSA-23-334-03 impacts PTC KEPServerEX, ThingWorx Kepware Server, and several others as listed in the advisory.
5
Are there any workarounds for ICSA-23-334-03?
As of now, there are no recommended workarounds for addressing ICSA-23-334-03.