PTC Kepware KEPServerEX是美国PTC公司的一个工业自动化数据连接解决方u200bu200b案。 PTC Kepware KEPServerEX 6.14.263.0 及之前版本存在安全漏洞,该漏洞源于 Web 服务器使用基本身份验证来保护用户凭据,攻击者利用该漏洞可以通过 ARP 欺骗执行中间人 (MitM) 攻击,以获取 Web 服务器的明文凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PTC | Kepware KEPServerEX | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Kepware Server | 0 ~ 6.14.263.0 | - |
|
| PTC | ThingWorx Industrial Connectivity | 8.0 ~ 8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29445 | 7.8 HIGH | Uncontrolled Search Path Element in PTC's Kepware KEPServerEX |
| CVE-2023-29444 | 6.3 MEDIUM | Uncontrolled Search Path Element in PTC's Kepware KEPServerEX |
| CVE-2023-29446 | 4.7 MEDIUM | Improper Input Validation in PTC's Kepware KEPServerEX |
No comments yet