Home/Product/ptc kepware kepserverex
Product

ptc kepware kepserverex

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-29447
>= 6.0.2107.0 and <= 6.14.263.0
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the w
5.7MEDIUM
CVE-2023-29446
>= 6.0.2107.0 and <= 6.14.263.0
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious
4.7MEDIUM
CVE-2023-29445
>= 6.0.2107.0 and <= 6.14.263.0
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adv
7.8HIGH
CVE-2023-29444
>= 6.0.2107.0 and <= 6.14.263.0
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adv
6.3MEDIUM
CVE-2023-3825
>= 6.0.0 and <= 6.14.263
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncon
7.5HIGH
CVE-2022-2848
< 6.12
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
9.1CRITICAL
CVE-2022-2825
< 6.12
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
9.8CRITICAL
CVE-2020-27267
all versions
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator
9.1CRITICAL
CVE-2020-27265
all versions
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregato
9.8CRITICAL
CVE-2020-27263
all versions
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregato
9.1CRITICAL
CVE-2013-2789
< 5.12.140.0
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a den
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin