« Volver al listado

CVE-2023-29446

Estado: ModificadaMedia (4.7)—

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-29446",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-29446",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-14T17:23:25.379414Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ot-cert@dragos.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "ot-cert@dragos.com",
      "affectedData": [
        {
          "vendor": "PTC",
          "product": "Kepware KEPServerEX",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "0",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Kepware Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "0",
              "lessThanOrEqual": "6.14.263.0"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "PTC",
          "product": "ThingWorx Industrial Connectivity",
          "versions": [
            {
              "status": "affected",
              "version": "8.0",
              "versionType": "0",
              "lessThanOrEqual": "8.5"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-10T21:15:08.603",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ot-cert@dragos.com"
    },
    {
      "url": "https://www.dragos.com/advisory/ptcs-kepserverex-vulnerabilities/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "ot-cert@dragos.com"
    },
    {
      "url": "https://www.ptc.com/en/support/article/cs399528",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ot-cert@dragos.com"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.dragos.com/advisory/ptcs-kepserverex-vulnerabilities/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ptc.com/en/support/article/cs399528",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ot-cert@dragos.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-40"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto una vulnerabilidad de validación de entrada incorrecta que podría permitir a un adversario inyectar una ruta UNC a través de un archivo de proyecto malicioso. Esto permite a un adversario capturar hashes NLTMv2 y potencialmente descifrarlos offline."
    }
  ],
  "lastModified": "2026-06-17T05:50:04.537",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ptc:kepware_kepserverex:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE266C92-959F-41CE-A8DA-DC3D336BC169",
              "versionEndIncluding": "6.14.263.0",
              "versionStartIncluding": "6.0.2107.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_kepware_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99455409-195C-418C-A227-E9C67E70C2F3",
              "versionEndIncluding": "6.14.263.0",
              "versionStartIncluding": "6.8"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ptc:thingworx_industrial_connectivity:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10F80877-E2FA-4800-B4EB-BC87E35A9441",
              "versionEndIncluding": "8.5",
              "versionStartIncluding": "8.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ot-cert@dragos.com"
}