CVE-2023-29446: PTC Kepware Kepserverex

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.

Affected products

  • PTC Kepware Kepserverex: from 6.0.2107.0, up to and including 6.14.263.0
  • PTC Thingworx Industrial Connectivity: from 8.0, up to and including 8.5
  • PTC Thingworx Kepware Server: from 6.8, up to and including 6.14.263.0

Published 2024-01-10. Last modified 2026-06-17.