Kepware · Kepware Kepserverex · CVE-2023-29446
**Name of the Vulnerable Software and Affected Versions**
Kepware KEPServerEX versions (affected versions not specified)
ThingWorx Kepware Server versions (affected versions not specified)
**Description**
The issue is related to insufficient input validation, which can be exploited by an adversary to gain access to confidential information. This can be achieved by uploading a malicious project file, allowing the adversary to inject a UNC path and capture NLTMv2 hashes, potentially cracking them offline.
**Recommendations**
For Kepware KEPServerEX, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For ThingWorx Kepware Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.