PTC Kepware KEPServerEX是美国PTC公司的一个工业自动化数据连接解决方u200bu200b案。 PTC Kepware KepServerEX 6.14.263.0 及之前版本存在安全漏洞,该漏洞源于容易通过恶意项目文件遭受 UNC 路径注入,通过诱骗用户加载项目文件并单击 GUI 中的特定按钮,攻击者可以获得 Windows 用户 NTLMv2 哈希值,并离线破解它们。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PTC | Kepware KEPServerEX | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Kepware Server | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Industrial Connectivity | 8.0 ~ 8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29445 | 7.8 HIGH | Uncontrolled Search Path Element in PTC's Kepware KEPServerEX |
| CVE-2023-29444 | 6.3 MEDIUM | Uncontrolled Search Path Element in PTC's Kepware KEPServerEX |
| CVE-2023-29447 | 5.7 MEDIUM | Insufficiently Protected Credentials in PTC's Kepware KEPServerEX |
No comments yet