Improper Validation of Certificate with Host Mismatch in PTC KEPServerEx
CVE-2023-5909
7.5HIGH
What is CVE-2023-5909?
KEPServerEX by Kepware is susceptible to a vulnerability where the software fails to properly validate certificates from clients. This could allow unauthorized users to connect to the system, potentially compromising sensitive data and control over connected devices. Organizations using KEPServerEX should apply the latest security updates to mitigate this risk.
Affected Version(s)
Industrial Gateway Server 0 <= 7.614
KEPServer Enterprise 0 <= 6.14.263.0
KEPServerEX 0 <= 6.14.263.0