peter bassill · operator
$ cve CVE-2023-0755 JSON

CVE-2023-0755

9.8
CRITICAL · CVSS 3.1 · EPSS 11.8% (pctl 96)

Patch early

EPSS 11.8% — above the 10% action threshold.

Description

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS11.78% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-129
On CISA KEVno
Public exploitnone known
Published2023-02-23
Last modified2026-06-17

Affected (9)

VendorProduct
gedigital industrial gateway server
ptckepware server
ptckepware serverex
ptcthingworx .net-sdk
ptcthingworx edge c-sdk
ptcthingworx edge microserver
ptcthingworx industrial connectivity
ptcthingworx kepware edge
rockwellautomationkepserver enterprise

References

→ the Explorer  ·  watch your stack  ·  NVD