ZDI-CAN-20500: ZDI-23-1011: (Pwn2Own) PTC KEPServerEX Variant Resource Exhaustion Denial-of-Service Vulnerability
Published Jul 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of PTC KEPServerEX. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
PTC KEPServerEX
Event History
Jul 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20500?
ZDI-CAN-20500 is considered a critical vulnerability due to its potential to cause denial-of-service without requiring authentication.
2
How do I fix ZDI-CAN-20500?
To mitigate ZDI-CAN-20500, it is recommended to apply available patches from PTC for KEPServerEX.
3
Which versions of PTC KEPServerEX are affected by ZDI-CAN-20500?
All currently supported versions of PTC KEPServerEX are susceptible to the ZDI-CAN-20500 vulnerability.
4
Can ZDI-CAN-20500 be exploited remotely?
Yes, ZDI-CAN-20500 allows remote attackers to exploit the vulnerability without requiring any authentication.
5
What potential impacts does ZDI-CAN-20500 have?
ZDI-CAN-20500 can lead to a denial-of-service condition, making the affected system unusable.