CVE-2023-5909: Ge Industrial Gateway Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

Affected products

  • Ge Industrial Gateway Server: up to and including 7.614
  • PTC Keepserverex: up to and including 6.14.263.0
  • PTC Opc-Aggregator: up to and including 6.14
  • PTC Thingworx Industrial Connectivity: affected versions not specified
  • PTC Thingworx Kepware Edge: up to and including 1.7
  • PTC Thingworx Kepware Server: up to and including 6.14.263.0
  • Rockwellautomation Kepserver Enterprise: up to and including 6.14.263.0
  • Softwaretoolbox Top Server: up to and including 6.14.263.0

Published 2023-11-30. Last modified 2026-06-17.