Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kepware

First CVE: Aug 22, 2013Active for: 13 yearsTotal CVEs: 3

Kepware develops industrial automation and connectivity software, primarily KEPServerEX and LinkMaster, which bridge operational-technology systems and modern IT infrastructure. Its disclosed vulnerabilities cluster around configuration and resource-management weaknesses, including incorrect default permissions, infinite loops, out-of-bounds writes, and uncontrolled resource consumption, reflecting the complexity of managing stateful connections in OT gateway software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kepware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2013
12 years ago
Most Recent CVE
Jul 31, 2023
1,089 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3825HIGH
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC
Jul 31, 20237.524NONO
CVE-2020-13535HIGH
A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitr
Dec 18, 20207.820NONO
CVE-2013-2789HIGH
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via
Aug 22, 20137.820NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local1 (33.3%)
Network1 (33.3%)
Unknown1 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (66.7%)
High0 (0.0%)
Unknown1 (33.3%)
User Interaction
None2 (66.7%)
Unknown1 (33.3%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None1 (33.3%)
Unknown1 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kepware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kepware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kepware's Products

View all 2 CNAs →

Top CWEs