CVE-2024-6098: Ge Igs
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to unrestricted or unregulated resource allocation. This could cause a denial-of-service condition and crash the Kepware application. By default, these functions are turned off, yet they remain accessible for users who recognize and require their advantages.
Affected products
- Ge Igs: version V7.6x only
- PTC Kepware Kepserverex: version V6 only
- PTC Kepware Thingworx Kepware Server: version V6 only
- Software Toolbox Top Server: version V6 only
Published 2024-08-16. Last modified 2026-06-17.