Insufficiently Protected Credentials in PTC's Kepware KEPServerEX
CVE-2023-29447

5.7MEDIUM

What is CVE-2023-29447?

A vulnerability in PTC's KEPServerEX has been identified due to insufficient protection of user credentials. This issue arises from the usage of basic authentication by the web server, which can be exploited by adversaries to capture sensitive user credentials. Organizations utilizing KEPServerEX must take corrective measures to secure their systems, as exposed credentials can lead to unauthorized access and data breaches. It is recommended to review and implement security best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

Kepware KEPServerEX Windows 0 <= 6.14.263.0

ThingWorx Industrial Connectivity Windows 8.0 <= 8.5

ThingWorx Kepware Server Windows 0 <= 6.14.263.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Hanson of Dragos
.