Kepware develops industrial automation and connectivity software, primarily KEPServerEX and LinkMaster, which bridge operational-technology systems and modern IT infrastructure. Its disclosed vulnerabilities cluster around configuration and resource-management weaknesses, including incorrect default permissions, infinite loops, out-of-bounds writes, and uncontrolled resource consumption, reflecting the complexity of managing stateful connections in OT gateway software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kepware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3825HIGH
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC | Jul 31, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-13535HIGH A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitr | Dec 18, 2020 | 7.8 | 20 | NO | NO |
CVE-2013-2789HIGH The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via | Aug 22, 2013 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kepware.
Media articles that mention a CVE ID that affects a product developed by Kepware — matched by CVE ID, not by vendor name.