CVE-2023-29446
10.01.2024, 21:15
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
Vendor | Product | Version |
---|---|---|
ptc | kepware_kepserverex | 6.0.2107.0 ≤ 𝑥 ≤ 6.14.263.0 |
ptc | thingworx_kepware_server | 6.8 ≤ 𝑥 ≤ 6.14.263.0 |
ptc | thingworx_industrial_connectivity | 8.0 ≤ 𝑥 ≤ 8.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-40 - Path Traversal: '\\UNC\share\name\' (Windows UNC Share)An attacker can inject a Windows UNC share ('\\UNC\share\name') into a software system to potentially redirect access to an unintended location or arbitrary file.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References