CVE-2023-29447: Insufficiently Protected Credentials in PTC's Kepware KEPServerEX
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29447?
CVE-2023-29447 is considered a medium severity vulnerability due to the potential for unauthorized access to user credentials.
How do I fix CVE-2023-29447?
To mitigate CVE-2023-29447, it is recommended to disable basic authentication and implement stronger authentication mechanisms.
What systems are affected by CVE-2023-29447?
CVE-2023-29447 affects versions of PTC KEPServerEX from 6.0.2107.0 to 6.14.263.0 and PTC ThingWorx products within specified version ranges.
Can CVE-2023-29447 be exploited remotely?
Yes, CVE-2023-29447 can be exploited remotely, allowing attackers to capture user credentials over the network.
Is there a workaround for CVE-2023-29447?
A temporary workaround for CVE-2023-29447 includes restricting access to the web server or using VPNs for secure access.