← Back to browse · API

CVE-2023-0755

Severity
CRITICAL
CVSS
9.8
EPSS
0.11784
Risk score
43.32
CISA KEV
No
PoC
No
Published
2023-02-23
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2023-12773, GHSA-MQP8-25JM-W22W
Products
General Electric:Digital Industrial Gateway Server 0 ≤v7.612, Microsoft:.NET-SDK 0 ≤v5.8.4.971, PTC:Kepware KEPServerEX 0 ≤v6.12, PTC:ThingWorx Edge C-SDK 0 ≤v2.2.12.1052, PTC:ThingWorx Edge MicroServer (EMS) 0 ≤v5.4.10.0, PTC:ThingWorx Industrial Connectivity All Versions, PTC:ThingWorx Kepware Edge 0 ≤v1.5, PTC:ThingWorx Kepware Server 0 ≤v6.12, Rockwell Automation:KEPServer Enterprise 0 ≤v6.12
Sources
euvd EUVD-2023-12773

Description

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

References