Improper Input Validation in PTC's Kepware KEPServerEX
CVE-2023-29446
Key Information:
- Vendor
Ptc
- Vendor
- CVE Published:
- 10 January 2024
What is CVE-2023-29446?
An improper input validation vulnerability exists in PTC's Kepware KEPServerEX that allows attackers to manipulate the system by injecting a Universal Naming Convention (UNC) path through a malicious project file. This vulnerability could facilitate the unauthorized capture of NLTMv2 hashes, enabling potential offline cracking attempts. Organizations relying on these products should assess their systems and consider applying necessary updates and security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kepware KEPServerEX Windows 0 <= 6.14.263.0
ThingWorx Industrial Connectivity Windows 8.0 <= 8.5
ThingWorx Kepware Server Windows 0 <= 6.14.263.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
