The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
2023-02-23T22:15:11.427
2024-11-21T07:37:45.493
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ge | digital_industrial_gateway_server | ≤ 7.612 | Yes |
| Application | ptc | kepware_server | ≤ 6.12 | Yes |
| Application | ptc | kepware_serverex | ≤ 6.12 | Yes |
| Application | ptc | thingworx_.net-sdk | ≤ 5.8.4.971 | Yes |
| Application | ptc | thingworx_edge_c-sdk | ≤ 2.2.12.1052 | Yes |
| Application | ptc | thingworx_edge_microserver | ≤ 5.4.10.0 | Yes |
| Application | ptc | thingworx_industrial_connectivity | - | Yes |
| Application | ptc | thingworx_kepware_edge | ≤ 1.5 | Yes |
| Application | rockwellautomation | kepserver_enterprise | ≤ 6.12 | Yes |