CVE-2023-5909

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ge:industrial_gateway_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:keepserverex:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:opc-aggregator:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_industrial_connectivity:-:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:softwaretoolbox:top_server:*:*:*:*:*:*:*:*

History

06 Dec 2023, 19:54

Type Values Removed Values Added
First Time Ptc
Ptc thingworx Kepware Edge
Ptc thingworx Kepware Server
Rockwellautomation
Rockwellautomation kepserver Enterprise
Softwaretoolbox top Server
Ptc thingworx Industrial Connectivity
Ge industrial Gateway Server
Ptc keepserverex
Ge
Ptc opc-aggregator
Softwaretoolbox
CPE cpe:2.3:a:rockwellautomation:kepserver_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_kepware_edge:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:opc-aggregator:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_industrial_connectivity:-:*:*:*:*:*:*:*
cpe:2.3:a:ptc:keepserverex:*:*:*:*:*:*:*:*
cpe:2.3:a:softwaretoolbox:top_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ge:industrial_gateway_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*
CWE CWE-295
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-334-03 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 Nov 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-30 22:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-5909

Mitre link : CVE-2023-5909

CVE.ORG link : CVE-2023-5909


JSON object : View

Products Affected

ge

  • industrial_gateway_server

ptc

  • opc-aggregator
  • keepserverex
  • thingworx_kepware_server
  • thingworx_kepware_edge
  • thingworx_industrial_connectivity

softwaretoolbox

  • top_server

rockwellautomation

  • kepserver_enterprise
CWE
CWE-295

Improper Certificate Validation

CWE-297

Improper Validation of Certificate with Host Mismatch