CVE-2022-2848
Last modified
CVE-2022-2848 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. EPSS estimates a 3.37% chance of exploitation in the next 30 days.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ge | Industrial Gateway Server | < 7.612 |
| Ptc | Kepware Kepserverex | < 6.12 |
| Ptc | Opc-Aggregator | < 6.12 |
| Ptc | Thingworx Industrial Connectivity | All versions |
| Ptc | Thingworx Kepware Edge | < 1.4 |
| Ptc | Thingworx Kepware Server | < 6.12 |
| Rockwellautomation | Kepserver Enterprise | < 6.12 |
| Softwaretoolbox | Top Server | < 6.12 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-242-10Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-22-1454/Third Party Advisory, VDB Entry
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-242-10Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-22-1454/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2848?
How severe is CVE-2022-2848?
How do I fix CVE-2022-2848?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2847A vulnerability, which was classified as critical, has been …9.8
- CVE-2022-28470marcador package in PyPI 0.1 through 0.13 included a code-ex…9.8
- CVE-2022-28471In ffjpeg (commit hash: caade60), the function bmp_load() in…6.5
- CVE-2022-28477WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).6.1
- CVE-2022-28478SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traver…6.5
- CVE-2022-28479SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable …4.8
- CVE-2022-28480ALLMediaServer 1.6 is vulnerable to Buffer Overflow via Medi…9.8
- CVE-2022-28481CSV-Safe gem < 3.0.0 doesn't filter out special characters w…9.8
- CVE-2022-28487Tcpreplay version 4.4.1 contains a memory leakage flaw in fi…7.5
- CVE-2022-28488The function wav_format_write in libwav.c in libwav through …7.5
- CVE-2022-2849Heap-based Buffer Overflow in GitHub repository vim/vim prio…7.8
- CVE-2022-28491TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a co…9.8
Are you affected by CVE-2022-2848?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
