What is Kepware?
Kepware is PTC’s industrial connectivity platform that uses more than 150 communication drivers to collect data from PLCs, controllers and other industrial devices and presents it as a single, uniform source to SCADA, MES, historians and cloud applications through interfaces such as OPC UA, OPC DA and MQTT. Its best-known product is the Windows server KEPServerEX, renamed Kepware Server with version 7.0 in November 2025. In many plants Kepware is the translation layer between a patchwork of vendor-specific field protocols and the IT applications that want to consume their data.
🧠 What does Kepware actually do?
Kepware solves a long-standing problem: every PLC vendor speaks its own protocol, while the software above would rather talk to one standard interface. Kepware handles this in four ways:
- Protocol translation — drivers for Siemens S7, Allen-Bradley EtherNet/IP, Modbus TCP, Mitsubishi, Omron, DNP3, IEC 61850 and many more read the devices
- One data model — every value becomes a tag in a uniform tree, regardless of the source protocol
- Standard northbound interfaces — OPC UA, OPC DA (Classic), MQTT, REST and ThingWorx expose the same tags to several consumers at once
- Shielding the PLC — ten clients asking for the same value result in one poll to the controller rather than ten
🕰️ How did Kepware come about?
| Year | Milestone |
|---|---|
| 1995 | Kepware Technologies founded in Portland, Maine (USA) |
| 2009 | KEPServerEX version 5; the product grows into one of the most widely used OPC servers |
| January 2016 | PTC completes the acquisition for around USD 100 million, as a foundation for its ThingWorx IIoT platform |
| January 2017 | KEPServerEX version 6 introduces the REST-based Configuration API |
| November 2025 | Kepware Server 7.0 merges KEPServerEX and the parallel ThingWorx Kepware Server line; Kepware Edge 1.0 launches alongside it as a containerised Linux edition |
The OEM editions share the same core: KEPServer Enterprise is supplied by Rockwell Automation (often alongside FactoryTalk), Industrial Gateway Server by GE Digital and TOP Server by Software Toolbox. Vulnerabilities in Kepware therefore frequently apply to these products as well.
🔧 How is Kepware structured?
Every configuration follows the same three levels:
- Channel — one driver plus its communication settings, such as a network adapter or serial port
- Device — one physical controller within that channel, with IP address, model and timeouts
- Tag — one data point (address, data type, scan rate), optionally organised in tag groups
Plug-ins sit on top: IoT Gateway (MQTT, REST client and server, ThingWorx), DataLogger (writing to SQL databases), Advanced Tags (calculated tags), Security Policies and redundancy. The server runs as a Windows service and is managed through the Configuration client or the REST-based Configuration API, on port 57412 by default. The OPC UA server listens on port 49320 by default.
🔄 How does Kepware compare with the alternatives?
| Product | Vendor | Strength | Typical use |
|---|---|---|---|
| Kepware Server | PTC | Broadest driver library (150+), de facto standard | Central OPC server for SCADA, MES and historian |
| Matrikon OPC | Honeywell | Long OPC Classic heritage, tunnellers and DA/UA wrappers | Existing OPC DA estates |
| dataFEED OPC Suite | Softing | Compact gateway with OPC UA and MQTT | Smaller edge integrations |
| Ignition drivers | Inductive Automation | Drivers built into the SCADA platform | When Ignition is already the SCADA |
| HighByte Intelligence Hub | HighByte | Data modelling and contextualisation; relies on OPC UA or Kepware for PLC access | Industrial DataOps on top of Kepware or OPC UA |
| Litmus Edge | Litmus | Drivers, storage and analytics in one edge platform | IIoT and cloud projects |
In modern architectures Kepware is rarely the final destination: it delivers the raw tags, while a DataOps layer models them and publishes them to a Unified Namespace.
💶 How does Kepware licensing work?
Kepware is licensed per driver or per driver suite, for example the Siemens Suite, Allen-Bradley Suite, Modbus Suite, Manufacturing Suite (100+ drivers) or Advanced Manufacturing Suite (every driver). Plug-ins such as IoT Gateway and DataLogger are licensed separately. Besides perpetual licences with annual maintenance, PTC offers the Kepware+ subscription, which gives access to all drivers. Without a licence the software runs in a demo mode that stops after two hours — handy for testing, but disastrous if someone forgets to activate a production server.
🏗️ Where does Kepware sit in the Purdue model?
Kepware typically belongs at level 2 or 3 of the Purdue Model: close enough to the controllers to poll them, but below the IT boundary. A common pattern is a Kepware server inside the OT network that reads the PLCs, plus a second instance or an OPC UA or MQTT connection into a DMZ that hosts historian replicas and cloud connectors. Never let IT systems connect straight through the OT firewall to the Kepware server in the production zone.
🔐 How do you secure Kepware?
Kepware is an attractive target: a single server with read access, and often write access, to every PLC in a plant. Several serious vulnerabilities have been published, some of them critical:
| CVE | Year | Issue | CVSS | Affected versions |
|---|---|---|---|---|
| CVE-2020-27265 / -27263 | 2020 | Stack and heap overflows in the OPC UA stack (found by Claroty) | 9.8 / 9.1 | 6.0–6.9; patched per release, e.g. 6.9.584.0 |
| CVE-2022-2825 / -2848 | 2022 | Stack and heap overflows via OPC UA messages (Claroty, Pwn2Own Miami) | 9.8 / 9.1 | All versions before 6.12 |
| CVE-2023-29444 | 2023 | DLL search order hijacking in the installer (reported by Dragos) | 6.3 | Up to and including 6.14.263.0 |
Key hardening measures:
- Encrypted OPC UA endpoints only — disable the None security policy and use Basic256Sha256 or newer with Sign & Encrypt
- No anonymous access — user management with strong passwords and read or write rights per user group, optionally per tag through the Security Policies plug-in
- Manage certificates — trust only known client certificates; after upgrading to 7.0 (2048-bit certificates) clients must be trusted again
- Disable unused interfaces — enable OPC DA with DCOM, the REST server and the Configuration API only when they are needed
- Patch and isolate — follow PTC and CISA advisories and never expose the server to the internet
🛠️ How do you connect a Siemens S7 to OPC UA through Kepware?
A common scenario: reading an S7-1500 for a historian that speaks OPC UA.
- Choose the driver — the Siemens TCP/IP Ethernet driver uses absolute addresses; symbolic access to S7-1200/1500 requires the Siemens S7 Plus Ethernet driver
- Prepare the PLC in TIA Portal — for the classic driver, tick Permit access with PUT/GET communication and disable Optimized block access on the relevant data blocks, then download to the PLC
- Create a channel — select the driver and the network adapter facing the machine network
- Add a device — select model S7-1500, enter the IP address, rack 0 and slot 1, and set a sensible timeout (for example 1,000 ms)
-
Create tags — for example
DB10.DBD0as Float with a 1,000 ms scan rate; avoid 100 ms for everything, which loads the PLC needlessly - Configure the OPC UA endpoint — port 49320, Basic256Sha256 Sign & Encrypt only, anonymous login off
- Test with an OPC UA client — trust the client certificate in the OPC UA Configuration Manager and check that the tag quality reads Good
❓ Frequently asked questions
Is Kepware free?
No, Kepware is commercial software from PTC, licensed per driver, per driver suite or through a Kepware+ subscription. Without a licence Kepware runs in a demo mode that stops after two hours and must be restarted. That mode is fine for testing, not for production.
What is the difference between KEPServerEX and Kepware Server?
KEPServerEX and Kepware Server are the same product under a different name. With version 7.0 in November 2025, PTC merged KEPServerEX and ThingWorx Kepware Server into a single product called Kepware Server. Version 6 projects can be migrated.
Does Kepware run on Linux?
The classic Kepware Server is Windows software and runs on Windows 10/11 and Windows Server. For Linux, PTC offers Kepware Edge, which runs in containers and targets large-scale edge deployments. Not every driver is available in Kepware Edge.
What is the default port of the Kepware OPC UA server?
The Kepware OPC UA server listens on TCP port 49320 by default, with an endpoint URL such as opc.tcp://<server>:49320. The port can be changed in the configuration. Restrict access to this
port in the firewall to the clients that genuinely need Kepware.
Can Kepware send data to MQTT or the cloud?
Yes, Kepware can publish tags to an MQTT broker and exchange data over REST through the IoT Gateway plug-in. That lets Kepware feed cloud platforms, a Unified Namespace or DataOps software without them having to speak PLC protocols. Use TLS and authentication towards the broker.
Do you still need Kepware if PLCs support OPC UA natively?
Kepware often remains useful even when modern PLCs have their own OPC UA server. Older controllers only speak their native protocol, and a central Kepware server limits the number of connections per PLC. In a fully greenfield plant with only OPC UA-capable controllers, Kepware may be unnecessary.
📌 In summary
Kepware is the universal translation layer between industrial controllers and IT applications: more than 150 drivers at the bottom, OPC UA, MQTT and REST at the top. That central position also makes Kepware a crown jewel for attackers; place it carefully in the Purdue model, enable only encrypted endpoints and keep the version up to date.
