Improper Input Validation in PTC's Kepware KEPServerEX
CVE-2023-29446

4.7MEDIUM

What is CVE-2023-29446?

An improper input validation vulnerability exists in PTC's Kepware KEPServerEX that allows attackers to manipulate the system by injecting a Universal Naming Convention (UNC) path through a malicious project file. This vulnerability could facilitate the unauthorized capture of NLTMv2 hashes, enabling potential offline cracking attempts. Organizations relying on these products should assess their systems and consider applying necessary updates and security measures to mitigate this risk.

Affected Version(s)

Kepware KEPServerEX Windows 0 <= 6.14.263.0

ThingWorx Industrial Connectivity Windows 8.0 <= 8.5

ThingWorx Kepware Server Windows 0 <= 6.14.263.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Hanson of Dragos
.