Lucene search

K
nvd[email protected]NVD:CVE-2023-29447
HistoryJan 10, 2024 - 9:15 p.m.

CVE-2023-29447

2024-01-1021:15:08
CWE-522
web.nvd.nist.gov
3
kepserverex
web server
basic authentication
vulnerability
credentials

5.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Affected configurations

NVD
Node
ptckepware_kepserverexRange6.0.2107.06.14.263.0
Node
ptcthingworx_kepware_serverRange6.86.14.263.0
Node
ptcthingworx_industrial_connectivityRange8.08.5

5.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%

Related for NVD:CVE-2023-29447