VYPR
High severity7.5NVD Advisory· Published Jul 31, 2023· Updated Jun 17, 2026

CVE-2023-3825

CVE-2023-3825

Description

PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such an object is recursively defined, so an attack could send a maliciously created message that the decoder would try to decode until the stack overflowed and the device crashed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:kepware:kepserverex:*:*:*:*:*:*:*:*
    Range: >=6.0.0,<=6.14.263
  • Ptc/KEPServerEXllm-create2 versions
    6.0 to 6.14.263+ 1 more
    • (no CPE)range: 6.0 to 6.14.263
    • (no CPE)range: 6.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.