← Back

Kepware

kepware

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Kepserverex
kepserverex
Linkmaster
linkmaster

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kepware
1Kepserverex
Nov 21, 2024
Jul 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various obj...Show more
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such an object is recursively defined, so an attack could send a maliciously created message that the decoder would try to decode until the stack overflowed and the device crashed. Show less
1Kepware
1Linkmaster
Nov 21, 2024
Dec 18, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitrary code with NT SYSTEM privileges.
1Kepware
1Kepserverex
Apr 29, 2026
Aug 22, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 a...Show more
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.Show less