CVE-2023-29446
MEDIUMDescription
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
Is your site exposed to CVE-2023-29446?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ptc | kepware_kepserverex |
| ptc | thingworx_kepware_server |
| ptc | thingworx_industrial_connectivity |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-29446? +
How severe is CVE-2023-29446? +
What products are affected by CVE-2023-29446? +
How do I check if I'm vulnerable to CVE-2023-29446? +
Related Vulnerabilities
Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, …
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files …
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate …
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of …
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate …
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses …