9.1
CVSSv3

CVE-2022-2848

Published: 29/03/2023 Updated: 20/04/2023
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ptc thingworx industrial connectivity -

ptc thingworx kepware edge

ptc opc-aggregator

ptc kepware kepserverex

softwaretoolbox top server

rockwellautomation kepserver enterprise

ptc thingworx kepware server

ge industrial gateway server

ICS Advisories