Lucene search

K
cve[email protected]CVE-2023-29446
HistoryJan 10, 2024 - 9:15 p.m.

CVE-2023-29446

2024-01-1021:15:08
CWE-20
web.nvd.nist.gov
15
cve-2023-29446
input validation
unc path
malicious project file
nltmv2 hashes

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.

Affected configurations

NVD
Node
ptckepware_kepserverexRange6.0.2107.06.14.263.0
Node
ptcthingworx_kepware_serverRange6.86.14.263.0
Node
ptcthingworx_industrial_connectivityRange8.08.5

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "Kepware KEPServerEX",
    "vendor": "PTC",
    "versions": [
      {
        "lessThanOrEqual": "6.14.263.0",
        "status": "affected",
        "version": "0",
        "versionType": "0"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "ThingWorx Kepware Server",
    "vendor": "PTC",
    "versions": [
      {
        "lessThanOrEqual": "6.14.263.0",
        "status": "affected",
        "version": "0",
        "versionType": "0"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "ThingWorx Industrial Connectivity",
    "vendor": "PTC",
    "versions": [
      {
        "lessThanOrEqual": "8.5",
        "status": "affected",
        "version": "8.0",
        "versionType": "0"
      }
    ]
  }
]

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%

Related for CVE-2023-29446