CVE-2024-6098
Published: Aug 16, 2024
Modified: Aug 19, 2024
CVSS v3.1
5.3
Description
When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to unrestricted or unregulated resource allocation. This could cause a denial-of-service condition and crash the Kepware application. By default, these functions are turned off, yet they remain accessible for users who recognize and require their advantages.
| Vendor | Product | Versions |
|---|---|---|
PTC | Kepware ThingWorx Kepware Server | affected V6 |
PTC | Kepware KEPServerEX | affected V6 |
Software Toolbox | TOP Server | affected V6 |
GE | IGS | affected V7.6x |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now