CVE-2024-6098
PTC Kepware ThingWorx Kepware Server Allocation of Resources Without Limits or Throttling
When performing an online tag generation to devices which communicate
using the ControlLogix protocol, a machine-in-the-middle, or a device
that is not configured correctly, could deliver a response leading to
unrestricted or unregulated resource allocation. This could cause a
denial-of-service condition and crash the Kepware application. By
default, these functions are turned off, yet they remain accessible for
users who recognize and require their advantages.
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
GE · IGSPTC · Kepware KEPServerEXPTC · Kepware ThingWorx Kepware ServerSoftware Toolbox · TOP Server¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →