CVE-2023-0754: Ge Digital Industrial Gateway Server

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

Affected products

  • Ge Digital Industrial Gateway Server: up to and including 7.612
  • PTC Kepware Server: up to and including 6.12
  • PTC Kepware Serverex: up to and including 6.12
  • PTC Thingworx .net-SDK: up to and including 5.8.4.971
  • PTC Thingworx Edge C-SDK: up to and including 2.2.12.1052
  • PTC Thingworx Edge Microserver: up to and including 5.4.10.0
  • PTC Thingworx Industrial Connectivity: any version
  • PTC Thingworx Kepware Edge: up to and including 1.5
  • Rockwellautomation Kepserver Enterprise: up to and including 6.12

Published 2023-02-23. Last modified 2026-06-17.