CVE-2023-29447

MEDIUM

PTC Kepware Kepserverex - Insufficiently Protected Credentials

Title source: rule

Description

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Scores

CVSS v3 5.7
EPSS 0.0005
EPSS Percentile 16.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (3)

ptc/kepware_kepserverex < 6.14.263.0
ptc/thingworx_kepware_server < 6.14.263.0
ptc/thingworx_industrial_connectivity < 8.5

Timeline

Published Jan 10, 2024
Tracked Since Feb 18, 2026