CVE-2023-5908: Ge Industrial Gateway Server

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

Affected products

  • Ge Industrial Gateway Server: up to and including 7.614
  • PTC Keepserverex: up to and including 6.14.263.0
  • PTC Opc-Aggregator: up to and including 6.14
  • PTC Thingworx Industrial Connectivity: affected versions not specified
  • PTC Thingworx Kepware Edge: up to and including 1.7
  • PTC Thingworx Kepware Server: up to and including 6.14.263.0
  • Rockwellautomation Kepserver Enterprise: up to and including 6.14.263.0
  • Softwaretoolbox Top Server: up to and including 6.14.263.0

Published 2023-11-30. Last modified 2026-06-17.