CVE-2023-29447
MEDIUMPTC Kepware Kepserverex - Insufficiently Protected Credentials
Title source: ruleDescription
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.
Scores
CVSS v3
5.7
EPSS
0.0005
EPSS Percentile
16.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (3)
ptc/kepware_kepserverex
< 6.14.263.0
ptc/thingworx_kepware_server
< 6.14.263.0
ptc/thingworx_industrial_connectivity
< 8.5
Timeline
Published
Jan 10, 2024
Tracked Since
Feb 18, 2026