Kepware Kepserverex是美国Kepware公司的一个可与多种工业设备进行通讯的应用软件。该软件支持150多个通讯协议,支持通过单个平台为企业提供可靠实时的数据。 Kepware KepServerEX 6.14.263.0 及之前版本存在安全漏洞,该漏洞源于KEPServerEX 的安装程序容易受到 DLL 搜索顺序劫持,这可能允许攻击者使用恶意 DLL 重新打包安装程序,并诱骗用户安装木马软件,导致以管理员权限执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PTC | Kepware KEPServerEX | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Kepware Server | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Industrial Connectivity | 8.0 ~ 8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29445 | 7.8 HIGH | Uncontrolled Search Path Element in PTC's Kepware KEPServerEX |
| CVE-2023-29447 | 5.7 MEDIUM | Insufficiently Protected Credentials in PTC's Kepware KEPServerEX |
| CVE-2023-29446 | 4.7 MEDIUM | Improper Input Validation in PTC's Kepware KEPServerEX |
No comments yet