CVE-2024-6098
MEDIUMPTC Kepware ThingWorx Kepware Server V6 - Denial of Service via ControlLogix Tag Generation
Title source: llmDescription
When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to unrestricted or unregulated resource allocation. This could cause a denial-of-service condition and crash the Kepware application. By default, these functions are turned off, yet they remain accessible for users who recognize and require their advantages.
References (2)
Core 2
Core References
Various Sources
https://www.ptc.com/en/support/article/CS423892
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-11
Scores
CVSS v3
5.3
EPSS
0.0040
EPSS Percentile
31.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (4)
GE/IGS
V7.6x
PTC/Kepware KEPServerEX
V6
PTC/Kepware ThingWorx Kepware Server
V6
Software Toolbox/TOP Server
V6
Published
Aug 16, 2024
Tracked Since
Feb 18, 2026