An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
2024-01-10T21:15:08.603
2024-11-21T07:57:04.453
Modified
CVSSv3.1: 4.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ptc | kepware_kepserverex | ≤ 6.14.263.0 | Yes |
Application | ptc | thingworx_kepware_server | ≤ 6.14.263.0 | Yes |
Application | ptc | thingworx_industrial_connectivity | ≤ 8.5 | Yes |