CVE-2023-29446: Improper Input Validation in PTC's Kepware KEPServerEX
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29446?
CVE-2023-29446 is classified as a high severity vulnerability due to its potential for remote code execution through malicious project file injection.
How do I fix CVE-2023-29446?
To fix CVE-2023-29446, update to the latest version of PTC KEPServerEX or PTC ThingWorx products as advised by PTC.
What software is affected by CVE-2023-29446?
CVE-2023-29446 affects PTC KEPServerEX, PTC ThingWorx Kepware Server, and PTC ThingWorx Industrial Connectivity within specified version ranges.
What kind of attacks can CVE-2023-29446 lead to?
Exploitation of CVE-2023-29446 can lead to the capture of NTLMv2 hashes, allowing adversaries to potentially crack them offline.
Is there a known exploit for CVE-2023-29446?
As of now, there is no publicly disclosed exploit specifically for CVE-2023-29446, but the vulnerability itself poses serious risks if left unpatched.