Your review has been sent successfully

PTC Updates

2793
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

7 January, 2021

● Critical

2021-2287

Manufacturing

Description:

PTC has released security update to address a vulnerability in the following products:

  • KEPServerEX: v6.0 to v6.9
  • ThingWorx Kepware Server: v6.8 and v6.9
  • ThingWorx Industrial Connectivity: All versions
  • OPC-Aggregator: All versions

The following products may have a vulnerable component:

  • The following products may have a vulnerable component:
  • Rockwell Automation KEPServer Enterprise: v6.6.504.0 and v6.9.572.0
  • GE Digital Industrial Gateway Server: v7.68.804 and v7.66
  • Software Toolbox TOP Server: All 6.x versions

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service attack (DoS)
  • Buffer overflow

Best practice and Recommendations:

The CERT team encourages users to review PTC security advisory and apply the necessary updates:

PTC recommends users of the following products upgrade to the most current supported version:

  • Rockwell Automation KEPServer Enterprise
    • Version 6.6 should upgrade to Version 6.6.550.0
    • Version 6.9 should upgrade to Version 6.9.584.0
  • GE Digital Industrial Gateway Server
    • Versions 7.68.804 and 7.66 should update to Version 7.68.839.
  • Software Toolbox TOP Server

Last updated at 7 January, 2021

Rate the content

rate-icon
up icon