ZDI-23-1011: (Pwn2Own) PTC KEPServerEX Variant Resource Exhaustion Denial-of-Service Vulnerability
Published Jul 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of PTC KEPServerEX. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
PTC KEPServerEX
Event History
Jul 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1011?
The severity of ZDI-23-1011 is critical due to its potential to cause a denial-of-service condition.
2
How do I fix ZDI-23-1011?
To fix ZDI-23-1011, update PTC KEPServerEX to the latest version where the vulnerability is patched.
3
Who is affected by ZDI-23-1011?
All installations of PTC KEPServerEX are affected by ZDI-23-1011.
4
Can ZDI-23-1011 be exploited without authentication?
Yes, ZDI-23-1011 can be exploited without authentication, making it particularly dangerous.
5
What type of vulnerability is ZDI-23-1011?
ZDI-23-1011 is a remote denial-of-service vulnerability.